← Back to WISeRly
Security & Compliance
Last Updated: August 26, 2026
WISeRly is building a healthcare-focused security and compliance program aligned with HIPAA and HITECH. Clinical submission and PHI intake are currently disabled while hosting agreements, vendor evidence, and technical controls are completed and reviewed.
Independent status: WISeRly is not affiliated with or endorsed by CMS, is not an official WISeR participant, and provides preparation results rather than official determinations.
🔒
HIPAA Program in Progress
PHI intake remains disabled pending approval
🛡️
Security Roadmap
Administrative, physical, and technical controls under review
🔐
Protected Accounts
Hashed passwords, expiring sessions, and server-side authorization
⚡
Vendor Review
Hosting, routing, logging, and BAAs must be verified
HIPAA Safeguards
Administrative
- Customer BAA template consolidated into one authoritative agreement
- Formal HIPAA risk analysis, workforce training, incident response, and vendor-management documentation remain pre-launch requirements
- Subcontractor BAAs must be executed and verified before any vendor is permitted to handle PHI
Physical
- The current application origin runs on Replit
- The owner reports DigitalOcean receives traffic first; the executed DigitalOcean BAA and complete routing evidence are not yet stored in this project
- Clinical submission remains disabled until every system in the PHI data path is documented and approved
Technical
- PBKDF2 password hashing with migration of legacy hashes
- Hashed, expiring client and administrator sessions
- Server-side authorization on protected billing and administrator APIs
- Signed Stripe webhook verification and server-side subscription enforcement
- Clinical file, patient-name, and clinical-note submission controls disabled pending compliance approval
Breach Notification
PHI is not currently accepted. If PHI services are activated and a breach of unsecured PHI occurs, notification will follow applicable law and the executed BAA:
- Roles, recipients, deadlines, content, and retention will be determined under applicable law and executed agreements.
- No shorter notification period or completed response capability is promised on this public page.
Pre-Launch Security Requirements
- Complete a documented HIPAA Security Rule risk analysis
- Approve and test incident response and breach-notification procedures
- Verify vulnerability scanning, monitoring, alerting, penetration testing, and backup controls
- Review access controls, workforce device security, and audit-log retention
- Retain executed BAAs and current subprocessor evidence
Business Continuity
- Recovery objectives, backup retention, restoration testing, and failover architecture must be documented and validated before being offered as contractual commitments.
Subcontractors & BAAs
No vendor is authorized to handle PHI until its role is documented and any required BAA is executed and retained. The owner reports a DigitalOcean BAA request is in progress, but the executed copy and complete routing evidence are not yet in this project. Replit remains the current application origin. Stripe receives account and payment information but must not receive clinical data or patient identifiers.
Need Our Compliance Documentation?
Request the current Technical and Security Statement, BAA document for review, and available security questionnaire responses. WISeRly does not claim SOC 2 certification or an audited readiness report.
Request Documentation
© 2026 WISeRly LLC. All rights reserved. | Privacy Policy | Terms of Service | Disclaimers | BAA