A platform your security team can say yes to.
AbbaDox protects patient data with independently audited controls, encryption everywhere, and secure interoperability, so adopting us reduces operational risk instead of adding it.
Independently verified, continuously maintained.
Third parties assess our controls on a recurring basis. These are our current certifications and attestations.
HIPAA
We handle PHI under a HIPAA-compliant program, with Business Associate Agreements available for covered entities and their partners.
SOC 2
An independent audit of our controls for security, availability, and confidentiality. The report your security team knows how to read.
SOC 3
A public attestation of the same controls that you can share freely across your organization, no NDA required.
NIST CSF
Our security program is aligned to the NIST Cybersecurity Framework, giving you a familiar structure to map against your own.
Auditors and security teams can access the underlying reports in our Trust Center.
Defense in depth, from network to record.
Cloud-native since 2003, AbbaDox is built so security is layered into every part of the platform, not bolted on at the edge.
Encryption everywhere
Data is encrypted in transit with TLS and at rest with strong, industry-standard encryption. Keys are managed and rotated, never exposed to your workflow.
Access control & identity
Role-based access, least-privilege permissions, single sign-on, and multi-factor authentication keep every record reachable only by the people who should see it.
Infrastructure security
Hosted on hardened cloud infrastructure with network segmentation, audit logging, and ongoing monitoring so issues are caught and contained early.
Data residency. Your data is hosted in secure, dedicated cloud infrastructure. We'll walk your team through our hosting model and data-residency options during your security review.
Connect your ecosystem without widening your attack surface.
AbbaDox exchanges clinical data across 105 systems. Every connection is authenticated, encrypted, and logged.
Secure HL7 & FHIR
Clinical data moves over encrypted, authenticated HL7 and FHIR interfaces, not open endpoints.
Authenticated integrations
Integrations across PACS, EHR, and RCM connect through scoped credentials and monitored channels, access is granted narrowly and revocably.
Governed data exchange
Every exchange is logged and access-controlled, so there is a record of what data moved, where it went, and who touched it.
Curious how it all fits together? Explore the platform →
Built to stay up when your center can't slow down.
Imaging runs around the clock, so reliability can't be an afterthought. AbbaDox is engineered to keep working through the failures that take other systems offline, and our contractual uptime commitment and SLA are shared as part of your security review.
Redundant infrastructure
No single point of failure: services run across redundant systems so one fault doesn't stop your day.
Automated failover
When something breaks, traffic reroutes automatically, recovery doesn't wait on someone being paged.
Continuous backups
Data is backed up continuously with tested recovery, so an outage never means lost records.
Proactive monitoring
Systems are watched around the clock so problems are spotted and handled before they reach you.
What happens when something goes wrong.
The questions IT teams ask first, in one place. Our business continuity and disaster recovery plan is tested, and the detail behind each answer is available for your security review.
Uptime and SLA
Our Service Level Terms commit to at least 99.9% monthly uptime. Scheduled maintenance is capped at four hours a month, announced three business days ahead, and runs after 8 p.m. Eastern.
Recovery and backups
Database backups are encrypted and kept in a secure location outside our core data centers. Our recovery objectives are shared as part of your security review.
Incidents
If an incident affects your data, you hear it from us directly, in line with our contractual and regulatory obligations.
If CareFlow is unreachable
Loss of connectivity to CareFlow is a Severity 1 issue, handled by our 24/7 helpdesk.
Hosting
CareFlow runs in private clouds we own and operate, in Tier 4 Equinix data centers. We walk your team through our hosting model and data-residency options during your security review.
Your data if you leave
Data erasure and certificates of destruction are among the controls in our Trust Center. Request our security package for the details.
Continuity also runs the other way. When ransomware took Sky Lakes Medical Center offline in October 2020, CareFlow had a RIS scheduling patients and integrated with PACS within a week. Read the Sky Lakes story →
The controls behind the certifications.
Certifications capture a moment in time. These are the practices that hold every day in between.
Incident response
If something goes wrong, you hear it from us, promptly and clearly, in line with our contractual and regulatory obligations.
Vulnerability management
We scan, patch, and test on an ongoing cadence, so known risks don't sit and wait.
Workforce security
Access follows least privilege and ends with the role. Every team member completes regular security training.
Change & access review
Permissions and system changes are reviewed and logged, so nothing drifts out of policy unnoticed.
Where CareFlow Ora runs, and what it can touch.
Ora is the AI layer inside AbbaDox CareFlow: Ora Assist answers questions, and Ora workflows handle order intake, patient calls and follow-up. Your security team can put model and subprocessor questions to ours at security@abbadox.com.
Inside CareFlow
Ora uses the same CareFlow data your team already works in, under the same audit trail. PHI stays inside CareFlow under the same controls as the rest of your data.
What Ora can read and write
Ora Assist is read only: it looks things up in CareFlow and cannot change, send or delete anything. Ora workflows work on the same records your staff do, such as entering an order or booking an appointment.
Your team stays in control
Fax AI creates a pending appointment for staff to review and schedule. When a workflow cannot complete an item with confidence, it stops and puts the item on an exception list with the reason attached.
One audit trail
Every workflow action is logged in the same audit trail as a staff action, including a scheduler's correction.
Ora does not read images, interpret findings or write reports, and it makes no clinical decisions. See how Ora works →
The full picture, for the people who need it.
Our Trust Center is the live source of truth: SOC reports, security documentation, subprocessors, and real-time continuous-monitoring status. It's where your auditors and security team get the artifacts, not just the assurances.
Found something? Tell us.
Report a vulnerability or reach our security team at security@abbadox.com.
Have a security question? Talk to a human.
No demo, no pressure. Send your security team's questions to ours, and we'll walk you through anything on this page.
What IT asks next