HealthcareComing soon · Security Platform

One platform for HIPAA, HITECH, and patient-visible audit.

Hospitals, EHR vendors, payers, telehealth, and digital-health platforms operate inside an audit perimeter that doesn't forgive mistakes. Tessarac ships with a HIPAA Business Associate Agreement, HITECH-compliant breach notification hooks, and per-patient audit visibility customers can show their own end users.

Concentric authentication factors radiating from a central trust shield.

Regulatory posture

HIPAA + HITECH + 21 CFR Part 11 + state privacy laws.

Modern healthcare platforms map to HIPAA Security Rule technical safeguards, HITECH breach notification, 21 CFR Part 11 (electronic records), plus the patchwork of state privacy laws (CMIA in California, MHMDA in Washington). Tessarac's per-tenant compliance preset configures the baselines and ships the evidence.

  • HIPAA Business Associate Agreement available on the Paid plan
  • HITECH breach notification hooks — every detection that touches PHI fires the operator-defined notification webhook within the regulated window
  • 21 CFR Part 11 — electronic-records integrity via the hash-chained, tamper-evident audit log
  • CMIA (California Confidentiality of Medical Information Act) + MHMDA (WA My Health My Data Act) controls documented
  • Per-patient audit visibility — customers can show end users who accessed their record and when

The healthcare-shaped deployment

Patient identity, clinician identity, system identity, brokered access to EHR backends — one platform, one audit log, one BAA.

  • Single sign-on federation hub with token issuance flows.

    Patient identity (CIAM)

    Passkeys, magic links, social federation for the patient side. Branded hosted UI per affiliate brand. Per-tenant audit log surfaced inside the patient portal so users can see their own access history.

  • Multi-factor authentication challenge surface.

    Clinician + admin SSO

    Workforce SSO for clinical and admin staff. Smart-card sign-in available on Paid; required by default on Federal for VA / DoD healthcare deployments. SCIM provisioning from your HR system.

  • Concentric cordon rings showing graduated isolation tiers.

    Brokered access to EHR backends

    SSH, RDP, database protocol proxy for the systems that hold PHI. Every session MFA-challenged, every command logged, every screen recorded. Just-in-time approvals; zero standing privilege.

  • Append-only audit trail with hash-chained block visualization.

    Per-patient audit, exportable

    Every PHI access lands in the per-patient audit chain. Patients see their own record-access history. Hospitals export to their existing SIEM, any object-storage bucket they own, or to a syslog destination — opt out of Tessarac retention entirely if needed.

Why healthcare is different

The audit isn't optional and the patient is the second auditor.

In most industries the auditor visits once a year. In healthcare, the patient can request the access log on their own record at any time. Tessarac ships the patient-visible audit as a first-class feature so your customers don't have to build it.

  • Per-patient access history visible inside the patient portal — no separate engineering project
  • HIPAA-compliant log retention with operator opt-out — customers may opt out of Tessarac retention entirely
  • Tamper-evident audit chain — verify the chain from any starting block to any ending block
  • Reference deployment for hospital systems (active-active across two regions, with disaster-recovery runbook)
  • Reference deployment for EHR SaaS — per-customer logical isolation by default, with the Dedicated HSM add-on for per-customer key isolation

Talk to a Tessarac healthcare architect

Most healthcare replacement engagements are sized at 8-12 weeks. BAA available on the Paid plan.