
Compliance
How patient data is handled — a HIPAA-covered workflow, end to end.
- PHI minimization
PHI stays in the case channel
Send the prescription and records as you have them — patient identifiers are handled inside the HIPAA-covered case channel, like in any covered lab workflow. Outside that channel each case travels on its case ID: logs, analytics, and correspondence carry no identifiers they don't need.
- BAA
BAA in place
A BAA is in place with our infrastructure provider; a BAA with your practice is signed on request — ask and it is on your desk before the first file moves. When production routing is used, the chain stays covered end to end: a subcontractor BAA with the production lab, not a verbal understanding.
- Storage
Encrypted storage on US infrastructure
Case files are encrypted in transit and at rest, and they live on US infrastructure. File exchange runs over a BAA-covered business channel — never personal file-sharing accounts, never offshore servers.
- What we never do
No PHI in logs, analytics, or images
No patient names in logs, analytics, invoices, or URLs. No PHI in any published image — every render on this site was reviewed by eye, and sources carrying engraved patient identifiers were rejected rather than retouched.
- Portfolio
De-identified by default
Published work is de-identified. Clinical photography is published only with written patient authorization obtained through the treating clinic.
Retention period — to be published
How long files are retained after delivery, and when they are purged, is being finalized. The number will be published here.
This page describes our operating practices. It is not legal advice and does not replace your own compliance review.
Questions on the BAA, storage, or file handling — ask before you send the first case.
Send a Case