- Database and roles
- Encryption and signing keys
- Functions and permissions
- Sign-in pool
- Files and audit log prefix
- Database and roles
- Encryption and signing keys
- Functions and permissions
- Sign-in pool
- Files and audit log prefix
HIPAA’s Security Rule asks for administrative, physical and technical safeguards around electronic patient information. In a Panaceum HIPAA app the runtime underneath enforces the technical ones, so nobody (and no AI) has to remember to write them.
The technical safeguards, on in every HIPAA app from the first build and the same on every plan.
On shared hosting, every app still has its own database and roles, its own encryption and signing keys, its own functions with their own permissions, its own sign-in pool and its own prefix for files and audit logs.
An app’s functions can only reach that app’s own database, keys and storage. There are no wildcard permissions across apps.
Deleting an app drops its database, deletes its files and schedules its keys for deletion, so anything left in backups becomes unreadable.
An app can call an outside service only after the owner approves the exact host, so data can’t be sent somewhere unexpected.
Previews come with realistic, recent synthetic records. Prompts and attachments are screened for PHI and blocked if they contain it.
Before a release you see exactly which roles gained or lost access to which pages, records and fields.
Production accepts only a build already running in staging, approved by the app owner with a fresh MFA check.
Panaceum is in early access. Join the waitlist and we’ll send you an access key.