Security
Last Updated: 1 July 2026
Patient Campaign is built to handle protected health information (PHI) responsibly. We operate as a HIPAA Business Associate on behalf of the healthcare providers and organizations who use our platform, and we sign a Business Associate Agreement (BAA) with every customer whose use involves PHI. This page describes how we protect the information entrusted to us.
Our approach
We follow security-by-design and privacy-by-design principles, and we align our practices with widely recognized frameworks including the AICPA SOC 2 Trust Services Criteria and the NIST 800-series. We do not currently hold formal SOC 2, ISO 27001, or similar certifications, and we do not claim to. We use these frameworks as a design reference and improve our program on an ongoing basis.
How security is managed
Security is owned by Patient Campaign's leadership and supported by a dedicated security contractor and our development team, who handle security across the platform. Responsibilities include implementing and maintaining safeguards, reviewing risks, and responding to incidents. Personnel with access to systems that handle PHI receive security awareness guidance and are expected to report any suspected security issue promptly.
Hosting and infrastructure
Patient Campaign is hosted on Amazon Web Services (AWS) in the United States under a signed Business Associate Agreement. Our infrastructure runs in AWS data centers, which maintain independent SOC 2 / SSAE-18 attestations and enforce physical and environmental controls. We use multi-availability-zone deployment for high availability and cross-region backups for disaster recovery.
Encryption
Data is encrypted in transit using strong, current TLS protocols (TLS 1.2 or higher) and at rest using AES-256. Customer data is logically separated at the application layer.
Access controls
Access to production systems and customer data is restricted to authorized personnel on a need-to-know basis. We maintain audit trails of changes to sensitive data, including the time of the change and the user who made it.
Secure development
Security is addressed throughout our development lifecycle. We use source control, change management, and defect tracking, apply secure coding practices (including input validation, output encoding, access control, and protection against common web vulnerabilities), and perform code review and testing before changes reach production.
Monitoring and logging
We monitor our production infrastructure and analyze logs to detect potential issues and alert relevant personnel. Our systems maintain audit trails of changes to sensitive data.
Vulnerability management
We use vulnerability scanning and engage third-party penetration testing to identify weaknesses. Findings are triaged by severity and remediated on a risk-prioritized basis, and results inform our ongoing risk assessment.
Incident response
We maintain a written incident-response plan that defines how we identify, classify by severity, and respond to security and privacy incidents. In the event of a material incident affecting customer data, we will notify affected customers in accordance with our contractual and legal obligations, including applicable HIPAA breach-notification requirements.
Disaster recovery and backups
We maintain a written disaster-recovery plan with defined recovery objectives. Backups are encrypted using AES-256, and we rely on multi-zone and cross-region infrastructure to protect against location-specific failures.
Subprocessors and vendors
We rely on a limited set of subprocessors to operate the platform. Where a subprocessor may handle PHI, we put an appropriate Business Associate Agreement or data-protection agreement in place and assess that the vendor maintains suitable administrative, physical, and technical safeguards. A current list of subprocessors is available to customers on request.
Customer BAAs
For customers whose use of Patient Campaign involves PHI, we execute a Business Associate Agreement that governs how PHI is used, disclosed, protected, and returned or destroyed. PHI processed on behalf of a customer is handled under that BAA and applicable law, not under our general website policies.
Responsible disclosure
If you believe you have found a security vulnerability, please report it to security@patientcampaign.com. We appreciate responsible disclosure and will investigate all legitimate reports.
Questions
For security questions, contact security@patientcampaign.com
