Security and Compliance
PACE Pro builds and delivers marketing content for local businesses, including medical practices and health systems, and, when a practice turns the feature on, asks patients for feedback after a visit. Where PACE handles patient information it acts as a business associate under HIPAA, and the platform is built on that basis. This page summarises the controls in place. Every control listed is one we verify on our production systems, and our full Security and Compliance Statement, with evidence, is available to a client's IT or compliance team through their PACE contact.
What PACE holds, and what it never holds
The only patient information PACE holds is what the feedback feature needs: an appointment reference, a first name, the contact the patient consented to be reached on, the consent itself, the visit time, and the provider and clinic. PACE never receives or stores diagnoses, notes, results, documents, insurance or payment information. Everything else PACE processes is the practice's own marketing content and its public reviews.
Agreements
- Business Associate Agreements with every subprocessor that touches patient data: our hosting provider, our email and text messaging provider, and our AI provider, whose HIPAA-ready configuration is enforced on our account.
- A Business Associate Agreement with each healthcare client before any patient data flows. Until it is signed, only synthetic test data is used.
- Data is processed and stored in the United States.
Encryption
- In transit: TLS 1.2 and 1.3 only, with HTTP Strict Transport Security on every PACE host.
- At rest: live data on encrypted storage; backups AES-256 encrypted, verified, kept locally and offsite in a private store.
- Credentials and patient identity fields: encrypted in place under separate keys held outside the database; patient identity fields live in their own database, looked up by keyed hash, with every read logged.
Access control
- Servers accept key-based administrative access only, behind a host firewall with brute-force banning and automatic security patching.
- Every PACE administrator uses multi-factor authentication, with role-based limits on what each person can do. When PACE staff open a client's account it is logged, and PACE staff never appear in the client's own team list.
- Client sessions expire on a fixed schedule and on inactivity, logins lock after repeated failures, and roles are granted per account. A view-only role exists for outside vendors and is enforced at the API. Multi-factor authentication for client users is available per account.
Audit and monitoring
- Every read of leads, reviews and patient survey responses is logged with who, what, how many, when and from where.
- Every configuration and credential change is recorded. Every data export and every delivery to a client's own systems is logged.
- Automated jobs watch for and destroy any unencrypted copy of data outside its home.
Built-in data handling rules
- Minimum necessary. Reports show aggregates; patient comments are visible only to the practice's own staff.
- Consent first. No message goes to a patient without consent for that channel; one request per visit, a cap across the practice, quiet hours, and opt-out honoured everywhere.
- No card data. Payment details are tokenised in the browser by our payment gateway; PACE never sees a card number.
- No tracking on patient-facing pages. Session recording tools are blocked for healthcare accounts and PACE adds no advertising pixels to the content it delivers.
- AI under a BAA. Patient data is processed only through our AI provider's covered interface under our agreement, and is not used to train models.
- Test environments never hold patient data. Our staging and preview systems run on separate databases with invented practices and invented people.
Integrations
- Data export keys are scoped to one client organization, stored hashed, revocable at any time, rate limited and logged on every call.
- A key or secret is never sent in an email. The recipient confirms their email address with a one-time code, the credential is created at that moment and shown once, and the link then dies.
- Data PACE delivers into a client's systems is signed so the receiving system can verify it came from PACE, and production delivery is enabled only after the agreements are in place.
- On a client's website PACE publishes only content it created and never modifies the client's own pages.
Operations
- Nothing reaches production without running on a staging system first; releases carry automated checks and roll back automatically if the new version is unhealthy.
- Nightly verified backups with a documented restore procedure, and a fresh encrypted snapshot before every release.
- We will notify an affected client of any security incident involving patient data without unreasonable delay and within the period set in our agreement, so the client can meet its own obligations.
Questions
A client's IT or security team can request the full statement, evidence for any control above, or a walkthrough of the architecture through their PACE contact. Evidence is shared directly with a named technical contact. Security researchers who believe they have found a vulnerability can reach us at security@pacepro.io.