Security and Compliance Built Into Every Layer

Moonshot Clinic is built from the ground up for HIPAA compliance. We don't bolt security on as an afterthought -- it's in the architecture.

HIPAA BAA Included AES-256 Multi-AZ EPCS Certified

Authentication

Every authentication mechanism is designed to prevent credential theft, session hijacking, and unauthorized access -- not just check a compliance box.

Data Isolation

Every clinic's data is isolated at the database level. There is no configuration that allows one tenant to access another's records -- the database enforces this, not application code.

Encryption

Data is encrypted everywhere it exists -- at rest, in transit, and at the field level for the most sensitive identifiers.

Audit Logging

Every clinical action, login attempt, and record access is logged to an immutable audit trail. This is not optional and cannot be disabled.

Business Associate Agreement

Every plan includes a BAA. No upgrade required, no sales call, no waiting period.

Download our BAA immediately -- no form, no email gate. BAA signing is built into the onboarding wizard so you're covered from the moment you create your account.

Download BAA (PDF)

Infrastructure

The entire stack runs on AWS with redundancy, automated failover, and continuous monitoring.

Rate Limiting

API abuse, credential stuffing, and brute-force attacks are stopped before they reach your data.

Data Portability

Your data is yours. Export everything -- patients, charts, labs, billing history -- at any time in standard formats. No lock-in, no export fees, no data hostage.

If you cancel your account, your data remains accessible for 90 days so you can complete your migration on your schedule. After that, it's securely deleted per HIPAA requirements.

Compliance Certifications

We don't just say we're compliant. Here's where we stand on every relevant standard.

🏥

HIPAA Compliant

BAA provided on all plans

Active
📝

SureScripts Certified

E-prescribing network

Active
🔒

EPCS Enabled

DEA-compliant controlled substances

Active
💳

Stripe PCI-DSS

Level 1 payment security

Active
🛡

SOC 2 Controls

Type II audit

In Progress

Your patients' data deserves better than "good enough."

Start your free trial with full HIPAA compliance from day one. BAA included.