Security & Trust
Built for trust — by design, not retrofit.
Moxcares handles PHI for clinics every day, and an AI staff member works inside that same data. Here's exactly how we keep it safe — without embellishment.
This page is maintained by the Moxcares team to answer common security and privacy questions about Moxcares. It is not an independent certification or audit report.
Built for trust
By design, not retrofit
Security and privacy were built into Moxcares from the first commit, not added after the fact. Every workflow is designed around least-privilege access, clear accountability, and patient-centered consent.
PHI-safe boundaries
Separate operational work from clinical authority
Access follows roles and clinical designations. An owner or administrator without clinical authority must state a recorded reason to read a chart. Patient scheduling messages follow consent and quiet-hours rules; clinical messages and attachments use authenticated communication.
Consent
Consent checked at every send, in the core
Messages are simply never sent to patients who haven't consented or who've opted out — enforced at the sending chokepoint, not a checkbox on a screen.
Access control
Server-side, on every request, down to collect-vs-refund
Owners, admins, staff, and practitioners each see exactly what their role permits — enforced on the server, on every request, never in the browser. Permissions are granular enough to separate who can collect a payment from who can issue a refund.
Account security
Multi-factor authentication for clinic users
Clinic-user access uses verified email-and-password credentials and multi-factor authentication. Role and designation controls apply alongside authentication.
Encryption
TLS 1.2+ in transit; AES-256 at rest
Data is encrypted at rest with AES-256 under Google Cloud-managed encryption keys, and in transit with TLS 1.2+ on Google Cloud. We have BAAs with every subprocessor that touches PHI, and card data never enters Moxcares.
Audit trail
Append-only audit trail
Every action that touches patient data is recorded in an audit log that is append-only at the database privilege layer. Every entry is attributed to a typed, accountable actor: a staff member, a patient's own verified self-service action, the AI staff member, or the system.
Integrity is verifiable on demand, and compliance exports ship with the verification verdict and everything needed to independently re-verify them. Audit records have six-year retention; your practice's clinical-record retention policy remains a separate responsibility.
Append-only
Enforced at the database privilege layer. The application has no path to modify or delete an entry.
Hash-chained
Entries are cryptographically chained per clinic, so any alteration or reordering becomes detectable.
Anchored daily
Chain heads are written to retention-locked, write-once storage once every 24 hours.
AI accountability
When AI acts, the record says so.
Mox is a distinct actor in the audit trail, timestamped and tied to the staff member who assigned that duty. Patients are always told when they're talking to an AI assistant, and can reach a person at any point.
A distinct actor type
Mox is never a shared service account and never masquerades as a human. Every action is attributed to the AI actor.
No solo clinical writes
Nothing enters the clinical record without a human accepting the AI's proposal.
No solo financial changes
Payment collection and refunds require authorized staff actions. The AI receptionist and AI staff member do not collect payments.
No PHI for training
We don't train models on your data. AI processing runs under the same BAA-covered infrastructure.
Chart access
Reads are logged, not just writes.
Most systems
- —Logs what changed in the chart
- —Read access is often invisible
- —Proving a complete access list is hard
Moxcares
- ✓Opening a chart, viewing a document, running "ask the chart"
- ✓Each entry names the actor, patient record, and exact time
- ✓"Who accessed this chart?" is answerable in minutes
Data use
Your data is yours.
We do not train AI models on your PHI or sell it. Patient information is processed and disclosed only as permitted by the BAA. Records are retained for seven years after subscription end, or longer where law requires, with C-CDA and document exports available on request.
Not used for AI training
Your PHI is never used to train or improve general-purpose models.
Exportable while retained
Request C-CDA records and documents while subscribed or during the post-subscription retention period, subject to authorization and the BAA.
Safe by default
Least-privilege access, server-side authorization, consent gating, and unalterable audit logs are the default path.
Reporting
Found something? Tell us directly.
Security reports and vulnerability disclosures go to security@moxcares.com. Please include the affected service and enough detail to help us investigate, without sending patient information. Incident reporting to clinics follows our BAA. Customers with an active incident should use the same address and mark the subject urgent.
Email security@moxcares.comControls & posture
The short version for your compliance team
On SOC 2: we are not SOC 2 certified today, and we won't imply otherwise. We've built the platform to the controls a SOC 2 Type II audit examines — documented access control, change management, logging and monitoring — and we'll share our current control documentation with your team on request.
Want the full security packet?
Our vendor register and BAA are published in the Trust Center. Contact us for policy materials under NDA and security questionnaire support.
Request the security packet