One platform for HIPAA, HITECH, and patient-visible audit.
Hospitals, EHR vendors, payers, telehealth, and digital-health platforms operate inside an audit perimeter that doesn't forgive mistakes. Tessarac ships with a HIPAA Business Associate Agreement, HITECH-compliant breach notification hooks, and per-patient audit visibility customers can show their own end users.

Regulatory posture
HIPAA + HITECH + 21 CFR Part 11 + state privacy laws.
Modern healthcare platforms map to HIPAA Security Rule technical safeguards, HITECH breach notification, 21 CFR Part 11 (electronic records), plus the patchwork of state privacy laws (CMIA in California, MHMDA in Washington). Tessarac's per-tenant compliance preset configures the baselines and ships the evidence.
- HIPAA Business Associate Agreement available on the Paid plan
- HITECH breach notification hooks — every detection that touches PHI fires the operator-defined notification webhook within the regulated window
- 21 CFR Part 11 — electronic-records integrity via the hash-chained, tamper-evident audit log
- CMIA (California Confidentiality of Medical Information Act) + MHMDA (WA My Health My Data Act) controls documented
- Per-patient audit visibility — customers can show end users who accessed their record and when
The healthcare-shaped deployment
Patient identity, clinician identity, system identity, brokered access to EHR backends — one platform, one audit log, one BAA.

Patient identity (CIAM)
Passkeys, magic links, social federation for the patient side. Branded hosted UI per affiliate brand. Per-tenant audit log surfaced inside the patient portal so users can see their own access history.

Clinician + admin SSO
Workforce SSO for clinical and admin staff. Smart-card sign-in available on Paid; required by default on Federal for VA / DoD healthcare deployments. SCIM provisioning from your HR system.

Brokered access to EHR backends
SSH, RDP, database protocol proxy for the systems that hold PHI. Every session MFA-challenged, every command logged, every screen recorded. Just-in-time approvals; zero standing privilege.

Per-patient audit, exportable
Every PHI access lands in the per-patient audit chain. Patients see their own record-access history. Hospitals export to their existing SIEM, any object-storage bucket they own, or to a syslog destination — opt out of Tessarac retention entirely if needed.
Why healthcare is different
The audit isn't optional and the patient is the second auditor.
In most industries the auditor visits once a year. In healthcare, the patient can request the access log on their own record at any time. Tessarac ships the patient-visible audit as a first-class feature so your customers don't have to build it.
- Per-patient access history visible inside the patient portal — no separate engineering project
- HIPAA-compliant log retention with operator opt-out — customers may opt out of Tessarac retention entirely
- Tamper-evident audit chain — verify the chain from any starting block to any ending block
- Reference deployment for hospital systems (active-active across two regions, with disaster-recovery runbook)
- Reference deployment for EHR SaaS — per-customer logical isolation by default, with the Dedicated HSM add-on for per-customer key isolation
Talk to a Tessarac healthcare architect
Most healthcare replacement engagements are sized at 8-12 weeks. BAA available on the Paid plan.