Security & Compliance

Security is architecture,
not a feature.

We design healthcare software for organizations handling protected health information, financial data, and clinical workflows. That means access control, encryption, isolation, and auditability are decided at the architecture stage — not patched in before a launch date.

Regulatory alignment

Built around HIPAA's technical safeguards

HIPAA compliance is a shared responsibility between a software vendor and the covered entity or business associate operating it. UIT's role is architecture: we design systems around HIPAA's technical safeguard requirements — access control, audit controls, integrity controls, and transmission security — so that a client's own compliance program has a solid technical foundation to build on.

We describe this as designing systems to support HIPAA-aligned environments. It is not a certification, and no software vendor is "HIPAA certified" — HIPAA compliance is assessed at the organization and deployment level, not stamped onto a product.

HIPAA technical safeguards we design for
  • Access control & unique user identification
  • Audit controls on systems containing PHI
  • Integrity controls to prevent improper alteration
  • Transmission security for data in motion
  • Automatic logoff & session controls
Design principles

Privacy and security are design inputs, not reviews

Two disciplines that shape every architecture decision before the first line of code is written.

Privacy by Design

Data collection is scoped to what a workflow actually needs. Purpose limitation, retention limits, and de-identification are architecture decisions, evaluated before data models are finalized.

Security by Design

Threat modeling, least-privilege defaults, and secure coding standards are applied from the first sprint — not introduced as a pre-launch checklist.

Data Minimization

Systems are built to collect, process, and retain only the data a defined workflow requires — reducing exposure by design, not by policy alone.

Technical capabilities

The controls behind every platform we build

Practices we apply as standard engineering discipline across client platforms.

Encryption in Transit & at Rest

Industry-standard encryption protects data moving across networks and data stored in databases and object storage, as a baseline engineering standard applied across our platforms.

Identity & Access Management

Centralized authentication, multi-factor options, and unique identity per user — never shared credentials for systems touching sensitive data.

Role-Based Access Control

Permissions scoped to role and workflow, with least-privilege defaults, so users and services see only the data their function requires.

Tenant Isolation

Multi-tenant SaaS platforms are architected so one client's data, configuration, and workload never cross into another's — enforced at the data and infrastructure layer, not just the application layer.

Audit Logging

Access to sensitive data is logged with who, what, and when — giving clients a real trail for internal review and incident investigation.

Secure API Design

Authenticated, rate-limited, and input-validated APIs, designed against common exploitation patterns from the first endpoint.

Data Protection

Backup, retention, and de-identification practices scoped to data sensitivity, with clear boundaries on what is retained, where, and for how long.

Infrastructure Security

Network segmentation, hardened deployment pipelines, and monitored cloud infrastructure, built and operated with production workloads in mind.

Ongoing Review

Security posture is revisited as platforms evolve, not fixed at launch — architecture decisions get re-examined as regulations and threats change.

On certifications

What we hold today, and what we don't

Precision matters here. This is a direct statement, not a marketing summary.

UIT Software does not currently hold independent third-party certifications such as SOC 2 or ISO 27001. These certifications are issued only after a formal audit by an accredited third party, and we do not claim to hold a SOC 2 report, an ISO 27001 certificate, or "HIPAA certification" — no such certification exists for a software vendor, as HIPAA compliance is assessed at the covered entity or business associate level.

What we do maintain is an architecture designed to align with HIPAA's technical safeguards and with the intent of common frameworks such as the SOC 2 trust services principles — security, availability, and confidentiality — as internal engineering design goals, not as audited or certified outcomes.

If your organization requires a specific certification, an executed Business Associate Agreement, or a formal audit as a condition of engagement, talk to us directly so we can scope what's needed for your compliance program before you commit to a build.

Have a specific compliance
requirement to discuss?

Tell us what your organization needs. We'll be direct about what we can and can't commit to.