Skip to main content

Compliance

Ciyex Hub is designed to meet healthcare regulatory requirements.

HIPAA Compliance​

Ciyex Hub and all first-party apps are built with HIPAA compliance:

  • Access Controls — Role-based access with OAuth2/JWT
  • Audit Controls — Comprehensive audit logging for all data access
  • Integrity Controls — Data validation and checksums
  • Transmission Security — TLS 1.3 for all communications
  • PHI Protection — Encrypted at rest and in transit

App Certification​

Each app in the marketplace displays its certifications:

CertificationDescription
HIPAAMeets HIPAA Security Rule requirements
SOC 2SOC 2 Type II compliance (when applicable)
ONCONC Health IT Certification (when applicable)

Business Associate Agreement (BAA)​

  • Ciyex Hub operates under a BAA with healthcare organizations
  • Third-party app vendors must sign a BAA before their apps are published
  • BAAs cover data processing, breach notification, and termination procedures

Data Retention​

  • App installation records are retained indefinitely for compliance
  • Audit logs are retained for a minimum of 6 years (HIPAA requirement)
  • Usage data is retained for billing and compliance purposes
  • Uninstalled app data is soft-deleted, not permanently removed

Incident Response​

In the event of a security incident:

  1. Affected apps are immediately suspended
  2. Practices are notified within 24 hours
  3. Investigation begins within 1 business day
  4. Full incident report provided within 30 days