Skip to main content

How we protect your record

A record that belongs to you has to be protected like it. This page lists the safeguards that exist today, stated the way we would want them checked, and then says plainly what we do not claim.

What is built today

myDxHub is built to HIPAA's safeguards. That is a description of the work, not a seal: each item below is a mechanism that exists in the product now, and each one is written so that it could be checked.

Encrypted in transit and at rest
Every connection to myDxHub uses strict transport security, and stored records and documents are encrypted on disk.
Access enforced at the database row
Who may open a record is decided by the database itself, row by row. A revoked provider’s access closes at the data layer, not in a flag the application is trusted to check.
The access log you see is the real audit trail
Every read of a patient record is written to an audit trail stamped with that record. What you see in your account is that same trail, not a summary prepared for you.
Access lapses after 30 days
Access to your record by anyone other than you lapses 30 days after their last open of it. A provider who needs a lasting copy exports it within that window.
Export your complete record any time
Your whole record is available as a ZIP, as JSON, or as a FHIR R4 bundle, from your own account, with no request form and nobody to ask.
Two-step verification available on every account
Any account can add a second step at sign-in with an authenticator app, from Settings.
HIPAA-eligible infrastructure
myDxHub runs on HIPAA-eligible AWS services under an executed business associate agreement.
Provider NPIs verified against the federal registry
When a practice registers or invites a clinician, the NPI is checked against the federal NPPES registry.
A designated Security and Privacy Official
myDxHub has designated a Security Official and a Privacy Official. Reach them at support@mydxhub.com with “Security” or “Privacy” in the subject line.
Sessions end after 30 minutes of inactivity
A signed-in session that has been idle for 30 minutes is signed out, with a warning at 25 minutes. A portal left open on a shared device should not stay open.
A published vulnerability disclosure route
Researchers who find a way to reach data they should not be able to reach have a documented place to report it: /.well-known/security.txt.
Designed to meet WCAG 2.1 AA
The site and the portal are built to the Web Content Accessibility Guidelines at Level AA. What that means in practice, and what is still rough, is on the accessibility statement.

What we do not claim

We do not claim any third-party certification. There is no such thing as a HIPAA certification: the law sets out safeguards, an organisation either meets them or does not, and nobody issues a seal for it.

Independent audits of myDxHub will be listed here when they exist, along with what they found.

Report a vulnerability

If you have found a way to reach data you should not be able to reach, we want to hear about it before anyone else does. The details, including what we ask of researchers and what we commit to in return, are at /.well-known/security.txt. You can also email support@mydxhub.com with “Security” in the subject line. Please do not include any patient data in your report.