Security — enterprise-grade protection.
Enterprise-grade protection for your practice and your patients’ data — built into every layer of the platform.
Trusted controls, independently verified.
The four marks in the hero, stated in full. Each card below is the wording published in layer 08 — nothing is added to it.
SOC 2
SOC 2-aligned controls, hosted in SOC 2 Type II certified data centers.
Control matrix on request.
PCI DSS
Payment processing complies with PCI Data Security Standards.
State regulations
Compliance with applicable state data-protection and record-retention laws.
The controls behind each mark are set out layer by layer in section 04.
Built for uptime, watched around the clock.
The same controls, grouped four ways.
Pick a domain to see which of the eight layers below covers it.
Access controls
MFA, role-based access, session limits and full audit logging.
Employee security
Background checks, least-privilege access and mandatory HIPAA training.
Data encryption
AES-256 at rest, TLS 1.3 in transit, keys held in HSMs.
Application security
Secure development, continuous scanning and annual third-party pen tests.
Infrastructure security
Certified data centers, geographic redundancy and hardened networks.
Business continuity & disaster recovery
Continuous backups, a 4-hour recovery objective and 1-hour data-loss ceiling.
Monitoring & incident response
24/7 monitoring, a security operations center and a tested response plan.
Compliance & certifications
HIPAA, SOC 2, PCI DSS and applicable state regulations.
Full detail for all eight layers is below.
Protection embedded in every layer.
Platinum protects the data of thousands of chiropractic practices and their patients. Security is embedded in every layer of the platform — from infrastructure and application design to operational processes and employee training.
- SOC 2 Type II certified data centers: 24/7 physical security, biometric access, video surveillance and environmental monitoring.
- Geographic redundancy: Data replicated across multiple regions for availability and disaster recovery.
- Network security: Enterprise-grade firewalls, intrusion detection/prevention (IDS/IPS) and DDoS mitigation.
- Isolated environments: Customer data logically isolated with strict tenant separation.
- At rest: All stored data encrypted with AES-256 — the standard used by financial institutions and government.
- In transit: All traffic between your devices and our servers encrypted with TLS 1.3.
- Key management: Keys managed in hardware security modules (HSMs) with automatic rotation.
- Database encryption: PHI and sensitive fields encrypted at the field level.
- Secure development lifecycle: Security reviews and automated testing at every stage of development.
- Vulnerability scanning: Automated and manual scans catch issues before production.
- Penetration testing: Independent third-party firms run annual penetration tests.
- Dependency management: Third-party libraries monitored for vulnerabilities and updated promptly.
- Code reviews: Every change peer-reviewed with a security-focused assessment.
- Multi-factor authentication: MFA available for all accounts and required for administrative access.
- Role-based access control: Granular permissions limit users to what their role needs.
- Session management: Automatic timeouts and concurrent-session limits.
- Password policies: Complexity, rotation and protection against compromised passwords.
- Audit logging: Every access to patient data logged with identity, timestamp and action.
- 24/7 monitoring: Continuous monitoring of systems, networks and applications with real-time alerting.
- Security operations center: A dedicated team monitors and responds to threats around the clock.
- Incident response plan: Documented, regularly tested procedures to identify, contain and remediate incidents.
- Threat intelligence: Threat-intelligence feeds proactively block emerging threats.
- Log retention: Security logs retained a minimum of 12 months for forensics and compliance.
- Automated backups: Continuous backups with point-in-time recovery.
- Recovery time objective: Designed for recovery within 4 hours of a major outage.
- Recovery point objective: Maximum data loss limited to 1 hour through continuous replication.
- Disaster recovery testing: Regular DR drills and failover tests.
- Redundant systems: Critical components run highly available with automatic failover.
- Background checks: All employees screened prior to hire.
- Security training: Mandatory awareness training at hire, refreshed quarterly.
- HIPAA training: Annual HIPAA-specific training and certification for all personnel.
- Least privilege: Access follows least-privilege with regular reviews.
- Confidentiality agreements: All employees sign confidentiality and non-disclosure agreements.
- HIPAA: Full compliance as a Business Associate — see our HIPAA Compliance page.
- SOC 2: SOC 2-aligned controls, hosted in SOC 2 Type II certified data centers; control matrix on request.
- PCI DSS: Payment processing complies with PCI Data Security Standards.
- State regulations: Compliance with applicable state data-protection and record-retention laws.
Watched, contained, recovered.
How the monitoring and continuity controls above work together when something needs attention.
-
Detect
Continuous monitoring of systems, networks and applications with real-time alerting — and threat-intelligence feeds proactively block emerging threats.
Real-time alerting -
Respond
A dedicated security operations center monitors and responds to threats around the clock, following documented, regularly tested procedures to identify, contain and remediate incidents.
Around the clock -
Recover
Continuous backups with point-in-time recovery — designed for recovery within 4 hours of a major outage, with maximum data loss limited to 1 hour through continuous replication.
Point-in-time recovery
What we never do with patient data.
Each line on the left is what the controls above rule out. Each line on the right is the control that rules it out.
- Let access to patient data go unlogged.
- Store or move patient data unencrypted.
- Mix one practice’s records in with another’s.
- Give staff blanket access to records.
- Ship a change to production unreviewed.
- Every access to patient data logged with identity, timestamp and action.
- AES-256 at rest, TLS 1.3 in transit, keys held in HSMs.
- Customer data logically isolated with strict tenant separation.
- Granular permissions limit users to what their role needs.
- Every change peer-reviewed with a security-focused assessment.
Full wording for each control is in the eight layers above.
“Platinum brought me peace of mind and saved not only man hours, but also those middle of the night ‘freak out’ moments.”
Answers practices ask for first.
Platinum is HIPAA compliant with SOC 2-aligned controls, hosted in SOC 2 Type II certified data centers. A control matrix is available on request.
All stored data is encrypted with AES-256, and all traffic between your devices and our servers is encrypted with TLS 1.3. Keys are managed in hardware security modules (HSMs) with automatic rotation, and PHI and sensitive fields are encrypted at the field level.
Access follows least privilege. Granular role-based permissions limit users to what their role needs, MFA is available for all accounts and required for administrative access, and every access to patient data is logged with identity, timestamp and action.
The platform is designed for recovery within 4 hours of a major outage, with maximum data loss limited to 1 hour through continuous replication. Backups are continuous with point-in-time recovery, and DR drills and failover tests run regularly.
We welcome responsible disclosure. Contact the security team at security@platinumsystem.com — full details are in the responsible disclosure section below.
Report a security issue.
We welcome responsible disclosure.
We value the security research community. If you discover a potential vulnerability, please contact our security team.
Attn: Security Team
Questions about how we protect your practice?
Talk to our security team about protecting your practice and patient data.