Trust and security

Built for sensitive workflows.

MyJourney is designed for clinics that need controlled access, auditability, and clear business-associate terms when HIPAA applies.

Security posture.

MyJourney is built so that a clinic's data stays the clinic's data. Access is least-privilege by default, every sensitive action is attributable, and program information is protected in transit and at rest. The controls below describe how the platform is engineered — not a marketing checklist.

Tenant isolation & access control

Each organization's records are separated by row-level security on the core clinical tables and enforced application-layer authorization across the platform, so records are returned only to a principal entitled to them. Access is role-based, organization-provisioned, and fails closed: if a permission cannot be confirmed, the request is denied rather than allowed.

Auditability

Authentication events and governed writes are recorded to a durable, append-only audit trail designed to survive partial failures, giving your team a dependable record for operational review, access investigations, and compliance support.

Data protection

PHI is encrypted at rest and in transit, secrets and encryption keys are managed outside application code, and administrative, technical, and physical safeguards — MFA, session invalidation, rate limiting, and monitoring — protect sensitive workflows.

Operations & resilience.

Security isn't only prevention — it's what happens around the edges: how long data lives, how it comes back after a fault, and what we do when something goes wrong.

Data retention

PHI is retained per your organization's instructions and the applicable Business Associate Agreement. On account closure or written request, data is deleted or returned as the agreement requires — your organization stays the custodian of its records.

Availability & recovery

Encrypted backups and a tested rollback path support recovery, and the platform is engineered to fail closed — denying access rather than exposing data — when a dependency is degraded.

Incident response

MyJourney maintains incident-response procedures. If a breach of unsecured PHI occurs, we notify the affected organization in line with the Business Associate Agreement and HIPAA breach-notification requirements.