Security & Trust

Built for trust — by design, not retrofit.

Moxcares handles PHI for clinics every day, and an AI staff member works inside that same data. Here's exactly how we keep it safe — without embellishment.

This page is maintained by the Moxcares team to answer common security and privacy questions about Moxcares. It is not an independent certification or audit report.

Built for trust

By design, not retrofit

Security and privacy were built into Moxcares from the first commit, not added after the fact. Every workflow is designed around least-privilege access, clear accountability, and patient-centered consent.

PHI-safe boundaries

Separate operational work from clinical authority

Access follows roles and clinical designations. An owner or administrator without clinical authority must state a recorded reason to read a chart. Patient scheduling messages follow consent and quiet-hours rules; clinical messages and attachments use authenticated communication.

Consent

Consent checked at every send, in the core

Messages are simply never sent to patients who haven't consented or who've opted out — enforced at the sending chokepoint, not a checkbox on a screen.

Access control

Server-side, on every request, down to collect-vs-refund

Owners, admins, staff, and practitioners each see exactly what their role permits — enforced on the server, on every request, never in the browser. Permissions are granular enough to separate who can collect a payment from who can issue a refund.

Account security

Multi-factor authentication for clinic users

Clinic-user access uses verified email-and-password credentials and multi-factor authentication. Role and designation controls apply alongside authentication.

Encryption

TLS 1.2+ in transit; AES-256 at rest

Data is encrypted at rest with AES-256 under Google Cloud-managed encryption keys, and in transit with TLS 1.2+ on Google Cloud. We have BAAs with every subprocessor that touches PHI, and card data never enters Moxcares.

Audit trail

Append-only audit trail

Every action that touches patient data is recorded in an audit log that is append-only at the database privilege layer. Every entry is attributed to a typed, accountable actor: a staff member, a patient's own verified self-service action, the AI staff member, or the system.

Integrity is verifiable on demand, and compliance exports ship with the verification verdict and everything needed to independently re-verify them. Audit records have six-year retention; your practice's clinical-record retention policy remains a separate responsibility.

01

Append-only

Enforced at the database privilege layer. The application has no path to modify or delete an entry.

02

Hash-chained

Entries are cryptographically chained per clinic, so any alteration or reordering becomes detectable.

03

Anchored daily

Chain heads are written to retention-locked, write-once storage once every 24 hours.

AI accountability

When AI acts, the record says so.

Mox is a distinct actor in the audit trail, timestamped and tied to the staff member who assigned that duty. Patients are always told when they're talking to an AI assistant, and can reach a person at any point.

A distinct actor type

Mox is never a shared service account and never masquerades as a human. Every action is attributed to the AI actor.

No solo clinical writes

Nothing enters the clinical record without a human accepting the AI's proposal.

No solo financial changes

Payment collection and refunds require authorized staff actions. The AI receptionist and AI staff member do not collect payments.

No PHI for training

We don't train models on your data. AI processing runs under the same BAA-covered infrastructure.

Chart access

Reads are logged, not just writes.

Most systems

  • —Logs what changed in the chart
  • —Read access is often invisible
  • —Proving a complete access list is hard

Moxcares

  • ✓Opening a chart, viewing a document, running "ask the chart"
  • ✓Each entry names the actor, patient record, and exact time
  • ✓"Who accessed this chart?" is answerable in minutes

Data use

Your data is yours.

We do not train AI models on your PHI or sell it. Patient information is processed and disclosed only as permitted by the BAA. Records are retained for seven years after subscription end, or longer where law requires, with C-CDA and document exports available on request.

✓

Not used for AI training

Your PHI is never used to train or improve general-purpose models.

✓

Exportable while retained

Request C-CDA records and documents while subscribed or during the post-subscription retention period, subject to authorization and the BAA.

✓

Safe by default

Least-privilege access, server-side authorization, consent gating, and unalterable audit logs are the default path.

Reporting

Found something? Tell us directly.

Security reports and vulnerability disclosures go to security@moxcares.com. Please include the affected service and enough detail to help us investigate, without sending patient information. Incident reporting to clinics follows our BAA. Customers with an active incident should use the same address and mark the subject urgent.

Email security@moxcares.com

Controls & posture

The short version for your compliance team

HIPAA
Signed BAA included on every plan
GCP
Hosted on Google Cloud (HIPAA-eligible services)
Encryption
AES-256 at rest · TLS 1.2+ in transit
Audit integrity
Hash-chained per clinic · anchored daily to write-once storage · verifiable on demand

On SOC 2: we are not SOC 2 certified today, and we won't imply otherwise. We've built the platform to the controls a SOC 2 Type II audit examines — documented access control, change management, logging and monitoring — and we'll share our current control documentation with your team on request.

Want the full security packet?

Our vendor register and BAA are published in the Trust Center. Contact us for policy materials under NDA and security questionnaire support.

Request the security packet