Compliance
Ciyex Hub is designed to meet healthcare regulatory requirements.
HIPAA Compliance​
Ciyex Hub and all first-party apps are built with HIPAA compliance:
- Access Controls — Role-based access with OAuth2/JWT
- Audit Controls — Comprehensive audit logging for all data access
- Integrity Controls — Data validation and checksums
- Transmission Security — TLS 1.3 for all communications
- PHI Protection — Encrypted at rest and in transit
App Certification​
Each app in the marketplace displays its certifications:
| Certification | Description |
|---|---|
| HIPAA | Meets HIPAA Security Rule requirements |
| SOC 2 | SOC 2 Type II compliance (when applicable) |
| ONC | ONC Health IT Certification (when applicable) |
Business Associate Agreement (BAA)​
- Ciyex Hub operates under a BAA with healthcare organizations
- Third-party app vendors must sign a BAA before their apps are published
- BAAs cover data processing, breach notification, and termination procedures
Data Retention​
- App installation records are retained indefinitely for compliance
- Audit logs are retained for a minimum of 6 years (HIPAA requirement)
- Usage data is retained for billing and compliance purposes
- Uninstalled app data is soft-deleted, not permanently removed
Incident Response​
In the event of a security incident:
- Affected apps are immediately suspended
- Practices are notified within 24 hours
- Investigation begins within 1 business day
- Full incident report provided within 30 days