Retour à l'accueil
Document Légal Officiel

Security & HIPAA Statement

Our technical standards, encryption policies, and HIPAA compliance framework.

Dernière mise à jour : 1er Octobre 2026·SpinaDesk™

1. Technical Safeguards & Encryption

SpinaDesk™ employs rigorous technical safeguards designed to protect practice and scheduling data:

  • In-Transit Encryption: All HTTP traffic and API calls use TLS 1.3 protocol with 256-bit encryption.
  • At-Rest Encryption: Database records and encrypted tokens are protected with AES-256 standards.
  • Infrastructure: Hosted in SOC 2 Type II and ISO 27001 certified cloud data centers.

2. HIPAA & Business Associate Agreement (BAA)

For Covered Entities operating within the United States subject to HIPAA regulations, SpinaDesk offers a standard Business Associate Agreement (BAA). The BAA defines mutual obligations regarding Protected Health Information (PHI) handling. To request a signed BAA, email compliance@spinadesk.com.

3. Access Control & System Monitoring

We enforce multi-factor authentication (MFA) for administrative operations, principle of least privilege access control, and continuous logging of critical system events.

Des questions sur nos mentions légales ?

Notre équipe juridique est disponible pour répondre à vos demandes de conformité.

Contacter support@spinadesk.com