Security & Trust
Built for trust — by design, not retrofit.
Moxcares handles PHI for clinics every day, and an AI staff member works inside that same data. Here's exactly how we keep it safe — without embellishment.
This page is maintained by the Moxcares team to answer common security and privacy questions about Moxcares. It is not an independent certification or audit report.
Built for trust
By design, not retrofit
Security and privacy were built into Moxcares from the first commit, not added after the fact. Every workflow is designed around least-privilege access, clear accountability, and patient-centered consent.
PHI-safe boundaries
Administrative surfaces are blind to PHI by construction
Billing, configuration and support surfaces operate on identifiers, not clinical content. Text messages are link-only — clinical details never travel over SMS. PHI is exposed only where it's clinically necessary, and only to roles that need it.
Consent
Consent checked at every send, in the core
Messages are simply never sent to patients who haven't consented or who've opted out — enforced at the sending chokepoint, not a checkbox on a screen.
Access control
Server-side, on every request, down to collect-vs-refund
Owners, admins, staff, and practitioners each see exactly what their role permits — enforced on the server, on every request, never in the browser. Permissions are granular enough to separate who can collect a payment from who can issue a refund.
Account security
MFA enforced for clinic staff (TOTP + SMS, 14-day enrollment grace)
Every staff account is email-verified, and multi-factor authentication is enforced using TOTP or SMS with a clear 14-day enrollment grace window so nobody is locked out of a live clinic day.
Encryption
TLS 1.2+ in transit; AES-256 at rest
Data is encrypted at rest with AES-256 under customer-managed encryption keys, and in transit with TLS 1.2+ on Google Cloud. We have BAAs with every subprocessor that touches PHI, and card data never enters Moxcares.
Audit trail
Append-only audit trail
Every action that touches patient data is recorded in an audit log that is append-only at the database privilege layer. Every entry is attributed to a typed, accountable actor: a staff member, a patient's own verified self-service action, the AI staff member, or the system.
Integrity is verifiable on demand, and compliance exports ship with the verification verdict and everything needed to independently re-verify them. Six-year retention, HIPAA-aligned.
Append-only
Enforced at the database privilege layer. The application has no path to modify or delete an entry.
Hash-chained
Entries are cryptographically chained per clinic, so any alteration or reordering becomes detectable.
Anchored daily
Chain heads are written to retention-locked, write-once storage once every 24 hours.
AI accountability
When AI acts, the record says so.
Mox is a distinct actor in the audit trail, timestamped and tied to the staff member who assigned that duty. Patients are always told when they're talking to an AI assistant, and can reach a person at any point.
A distinct actor type
Mox is never a shared service account and never masquerades as a human. Every action is attributed to the AI actor.
No solo clinical writes
Nothing enters the clinical record without a human accepting the AI's proposal.
No solo financial changes
Money-moving actions are proposed by AI and accepted by a person — never executed by AI alone.
No PHI for training
We don't train models on your data. AI processing runs under the same BAA-covered infrastructure.
Chart access
Reads are logged, not just writes.
Most systems
- —Logs what changed in the chart
- —Read access is often invisible
- —Proving a complete access list is hard
Moxcares
- ✓Opening a chart, viewing a document, running "ask the chart"
- ✓Each entry names the actor, patient record, and exact time
- ✓"Who accessed this chart?" is answerable in minutes
Data use
Your data is yours.
We don't train AI models on your PHI, and we never sell or share patient data. Your clinic's data is retained according to HIPAA-aligned schedules and made available to you for export and portability at any time, including after you leave.
Not used for AI training
Your PHI is never used to train or improve general-purpose models.
Exportable at any time
Your data is available for export and portability while you're a customer and after you leave.
Safe by default
Least-privilege access, server-side authorization, consent gating, and unalterable audit logs are the default path.
Reporting
Found something? Tell us directly.
Security reports and vulnerability disclosures go to security@moxcares.com. We acknowledge reports within one business day, we don't pursue good-faith researchers, and we'll keep you updated until the issue is closed. Customers with an active incident should use the same address and mark the subject urgent.
Email security@moxcares.comCertifications & posture
The short version for your compliance team
On SOC 2: we are not SOC 2 certified today, and we won't imply otherwise. We've built the platform to the controls a SOC 2 Type II audit examines — documented access control, change management, logging and monitoring — and we'll share our current control documentation with your team on request.
Want the full security packet?
We'll send our sub-processor list and a draft BAA for your counsel to review.
Request the security packet