Protect the information.
Encryption in transit and at rest, staff MFA and role-based permissions support the protection of patient information.
Security architectureMOXCARES TRUST CENTER
Understand how Moxcares protects information, supervises AI-assisted work and records actions. Clear controls. Accessible policies. Specific answers.
Maintained by Moxcares. This is a product-control overview, not an independent audit report or certification. Moxcares is not SOC 2 certified today.
SECURITY IN THE WORKFLOW
Security is part of access, documentation, communication and the activity history—not just a badge on a page.
Encryption in transit and at rest, staff MFA and role-based permissions support the protection of patient information.
Security architectureClinical proposals are reviewed by the responsible clinician. AI actions are attributable instead of appearing as an unnamed staff action.
Human-supervised AIChart access and changes are logged. Append-only, hash-chained audit records and daily anchors provide tamper-evident history.
Audit controlsPHI-handling vendors have BAAs in place. Non-PHI vendors serve separately defined purposes, such as payments and transactional email.
Vendors & data handlingPHI HANDLING
Patient information belongs in the appropriate clinical workflow, with controls on how it is accessed and used.
Patient information is not used to train AI models. PHI-processing services are subject to the relevant contractual arrangements and product controls.
Notification links direct patients to identity-verified communication. Clinical messages and attachments belong in the secured workflow, not in general notification content.
Ambient source audio is purged after processing. Transcripts and resulting clinical records are distinct from the source recording and follow their applicable handling requirements.
HUMAN-SUPERVISED AI
See the difference between AI preparation and an authorized action. Clinical responsibility remains with the clinician.
A demonstration of Mox preparing work, the team reviewing it and the activity history recording who took action.
POLICIES & AGREEMENTS
Review the published policies, then contact us for the details your procurement or security team needs.
DUE DILIGENCE, WITHOUT THE GUESSWORK
Need to review vendor scope, retention, incident response or access controls? Contact our team for the current information and any documents available for your review. We do not present unpublished policies as independently validated evidence.
security@moxcares.com