Trust at Indigo Health

Healthcare software lives or dies on trust. We built Indigo Health so that trust isn't a marketing claim — it's the architecture.

This page is the short version. The full policy library is available to prospects and customers under NDA, our Business Associate Agreement is available on request, and our team is happy to walk your security and compliance reviewers through any of it.

We're a business associate. That's it.

Indigo Health doesn't practice medicine, doesn't supervise clinicians, and doesn't decide what counts as a medical record. Our customers — the covered entities who treat patients — make those decisions, and we process protected health information only as their Business Associate Agreement directs.

A single, focused legal role means fewer surprises in your vendor risk review and a cleaner story for your regulators.

Your patient data isn't on our laptops. By design.

The single most important thing about how Indigo Health is built: identifiable patient data never lands on laptops, analytics warehouses, or test environments. We call this our minimum-access PHI architecture, and it's not a policy we ask people to follow — it's how the platform is built.

  • Protected health information stays inside our production trust boundary, meaning the database and the BAA-covered services that process it, and never spreads beyond it.
  • Our workforce does not routinely access protected health information to do their jobs. Internal tools surface the operational context our team needs, without exposing the underlying clinical content.
  • Access events are logged with user, time, and component metadata, and those logs carry no clinical content. The audit trail is rich; the data exposed by the audit trail is not.
  • Emergency break-glass access is the one exception to this architecture. It is available only to address an outage, a security incident, or a legal obligation. It is time-limited, requires two separate approvals, is fully logged, and is reviewed after the fact to confirm it was appropriate.

When a vendor is breached, every covered entity asks the same question: how much of our patient data did that vendor have sitting around? For Indigo Health, the honest answer is that it stayed within production controls, and it was never on anyone's laptop.

Built on infrastructure your reviewers already trust.

The platform runs on Microsoft Azure, on HIPAA-eligible services covered by Microsoft's Business Associate Agreement — inheriting enterprise-grade physical security and the global compliance certifications of one of the most heavily audited cloud platforms in the world. Data is encrypted in transit and at rest. For email that may carry protected health information, we use Paubox under a Business Associate Agreement.

We don't ask you to take our infrastructure on faith. We build on a foundation your own auditors have almost certainly assessed before.

A complete HIPAA Security Rule program — in writing.

Compliance shouldn't be a vibe. Ours is a documented library of policies and procedures, organized to the HIPAA Security Rule, so your reviewers can map our controls to the regulation directly.

Administrative

Risk analysis Workforce sanctions Onboarding Role-based access Training Contingency planning Logging and monitoring Backup and restore Business continuity and disaster recovery Incident response

Physical

Physical and environmental security Media protection and sanitization

Supply chain

Documented subprocessor management, with every third party that handles protected health information bound by a HIPAA-compliant agreement

Technical

Secure development Vulnerability management Change and configuration control Encryption key management Activity review

This isn't a slide deck. It's a maintained, version-controlled library that our own team operates against every day.

Vendor reviews, made easy.

We know what a vendor risk questionnaire looks like. We've designed our compliance posture so the answers are ready before you ask.

Document How to get it
Business Associate Agreement (template) Available on request
Full policy library (POL documents) Available under NDA
Complete subprocessor list with BAA status Available under NDA
Detailed procedures, runbooks, and evidence Internal — covered during deeper assessments

Evidence that holds up — not just claims.

Every control above produces a trail. Activity is captured in tamper-resistant, append-only logs, and governed evidence is retained in a write-once evidence repository built to satisfy a regulator, not just to check a box. When a reviewer asks to see something, the answer is documented evidence with a date on it, which we share during a security assessment or where the law requires it.

When something happens, you'll hear from us.

We notify affected customers of confirmed security incidents involving their protected health information, in accordance with the executed Business Associate Agreement and HIPAA's Breach Notification Rule. Incident triage, containment, and notification are governed by our Security Incident Response and Breach Notification Policy and its supporting procedures — so the response on the worst day isn't improvised.

Last reviewed: 2026-08-19

@ Talk to us

Contact form

Security and compliance reviewers — we'd rather meet you early than late. Reach us at security@indigo.health, or for general inquiries, hello@indigo.health.