Security & Trust

Built for trust — by design, not retrofit.

Moxcares handles PHI for clinics every day, and an AI staff member works inside that same data. Here's exactly how we keep it safe — without embellishment.

This page is maintained by the Moxcares team to answer common security and privacy questions about Moxcares. It is not an independent certification or audit report.

Built for trust

By design, not retrofit

Security and privacy were built into Moxcares from the first commit, not added after the fact. Every workflow is designed around least-privilege access, clear accountability, and patient-centered consent.

PHI-safe boundaries

Administrative surfaces are blind to PHI by construction

Billing, configuration and support surfaces operate on identifiers, not clinical content. Text messages are link-only — clinical details never travel over SMS. PHI is exposed only where it's clinically necessary, and only to roles that need it.

Consent

Consent checked at every send, in the core

Messages are simply never sent to patients who haven't consented or who've opted out — enforced at the sending chokepoint, not a checkbox on a screen.

Access control

Server-side, on every request, down to collect-vs-refund

Owners, admins, staff, and practitioners each see exactly what their role permits — enforced on the server, on every request, never in the browser. Permissions are granular enough to separate who can collect a payment from who can issue a refund.

Account security

MFA enforced for clinic staff (TOTP + SMS, 14-day enrollment grace)

Every staff account is email-verified, and multi-factor authentication is enforced using TOTP or SMS with a clear 14-day enrollment grace window so nobody is locked out of a live clinic day.

Encryption

TLS 1.2+ in transit; AES-256 at rest

Data is encrypted at rest with AES-256 under customer-managed encryption keys, and in transit with TLS 1.2+ on Google Cloud. We have BAAs with every subprocessor that touches PHI, and card data never enters Moxcares.

Audit trail

Append-only audit trail

Every action that touches patient data is recorded in an audit log that is append-only at the database privilege layer. Every entry is attributed to a typed, accountable actor: a staff member, a patient's own verified self-service action, the AI staff member, or the system.

Integrity is verifiable on demand, and compliance exports ship with the verification verdict and everything needed to independently re-verify them. Six-year retention, HIPAA-aligned.

01

Append-only

Enforced at the database privilege layer. The application has no path to modify or delete an entry.

02

Hash-chained

Entries are cryptographically chained per clinic, so any alteration or reordering becomes detectable.

03

Anchored daily

Chain heads are written to retention-locked, write-once storage once every 24 hours.

AI accountability

When AI acts, the record says so.

Mox is a distinct actor in the audit trail, timestamped and tied to the staff member who assigned that duty. Patients are always told when they're talking to an AI assistant, and can reach a person at any point.

A distinct actor type

Mox is never a shared service account and never masquerades as a human. Every action is attributed to the AI actor.

No solo clinical writes

Nothing enters the clinical record without a human accepting the AI's proposal.

No solo financial changes

Money-moving actions are proposed by AI and accepted by a person — never executed by AI alone.

No PHI for training

We don't train models on your data. AI processing runs under the same BAA-covered infrastructure.

Chart access

Reads are logged, not just writes.

Most systems

  • Logs what changed in the chart
  • Read access is often invisible
  • Proving a complete access list is hard

Moxcares

  • Opening a chart, viewing a document, running "ask the chart"
  • Each entry names the actor, patient record, and exact time
  • "Who accessed this chart?" is answerable in minutes

Data use

Your data is yours.

We don't train AI models on your PHI, and we never sell or share patient data. Your clinic's data is retained according to HIPAA-aligned schedules and made available to you for export and portability at any time, including after you leave.

Not used for AI training

Your PHI is never used to train or improve general-purpose models.

Exportable at any time

Your data is available for export and portability while you're a customer and after you leave.

Safe by default

Least-privilege access, server-side authorization, consent gating, and unalterable audit logs are the default path.

Reporting

Found something? Tell us directly.

Security reports and vulnerability disclosures go to security@moxcares.com. We acknowledge reports within one business day, we don't pursue good-faith researchers, and we'll keep you updated until the issue is closed. Customers with an active incident should use the same address and mark the subject urgent.

Email security@moxcares.com

Certifications & posture

The short version for your compliance team

HIPAA
Signed BAA included on every plan
GCP
Hosted on Google Cloud (HIPAA-eligible services)
Encryption
AES-256 at rest with CMK · TLS 1.2+ in transit
Audit integrity
Hash-chained per clinic · anchored daily to write-once storage · verifiable on demand

On SOC 2: we are not SOC 2 certified today, and we won't imply otherwise. We've built the platform to the controls a SOC 2 Type II audit examines — documented access control, change management, logging and monitoring — and we'll share our current control documentation with your team on request.

Want the full security packet?

We'll send our sub-processor list and a draft BAA for your counsel to review.

Request the security packet