HIPAA safeguards, enforced by the platform.

HIPAA’s Security Rule asks for administrative, physical and technical safeguards around electronic patient information. In a Panaceum HIPAA app the runtime underneath enforces the technical ones, so nobody (and no AI) has to remember to write them.

See pricing

What every HIPAA app gets.

The technical safeguards, on in every HIPAA app from the first build and the same on every plan.

Access rules per role
Every page, record and field is scoped to the roles in your plan: patients see their own records, staff see their panel. Changes show up as a security diff before release.
Audit logging from day one
Every read and write of health data is logged with who, what and when. Audit logs are stored where they can’t be edited or deleted.
Encryption everywhere
TLS in transit and encryption at rest for databases, files and backups, with optional field-level encryption for identifiers such as SSNs and member IDs.
Sign-in with MFA
Each app gets its own sign-in. Staff roles require multi-factor authentication, and sessions end after 15 minutes idle for staff (30 for patients) and 12 hours at most.
Synthetic data in every preview
Previews are filled with realistic synthetic patients. Real PHI is never allowed in the builder or a preview, so nothing leaks while you iterate.
Owner-approved releases
Production only takes a build that passed staging, approved by the app owner with MFA. Nothing an AI wrote reaches real patients unreviewed.

Each app is walled off.

On shared hosting, every app still has its own database and roles, its own encryption and signing keys, its own functions with their own permissions, its own sign-in pool and its own prefix for files and audit logs.

  • Least privilege

    An app’s functions can only reach that app’s own database, keys and storage. There are no wildcard permissions across apps.

  • Crypto-shredding on delete

    Deleting an app drops its database, deletes its files and schedules its keys for deletion, so anything left in backups becomes unreadable.

  • Approved outbound hosts only

    An app can call an outside service only after the owner approves the exact host, so data can’t be sent somewhere unexpected.

No real patient data in the builder.

  • Synthetic patients

    Previews come with realistic, recent synthetic records. Prompts and attachments are screened for PHI and blocked if they contain it.

  • Security diff

    Before a release you see exactly which roles gained or lost access to which pages, records and fields.

  • Releases need the owner

    Production accepts only a build already running in staging, approved by the app owner with a fresh MFA check.

What would you build first?

Panaceum is in early access. Join the waitlist and we’ll send you an access key.