Security & compliance
Built to support HIPAA compliance.
EXCEND™ holds protected health information on behalf of the practices that use it. This page states what is implemented, and what is not.
Implemented and in use.
- Dedicated PHI access log covering every read and write
- Strict organization-level data isolation
- Multi-factor authentication (TOTP) with single-use recovery codes
- Per-account lockout
- Session tokens stored hashed
- Server and client session timeouts
- Break-glass access requiring written justification, fully logged
- Right-of-access export
- Accounting of disclosures
- Strict Content Security Policy with no inline-script vector
- Optional HIPAA mode mandating MFA
- Encryption in transit and at rest
No software makes a practice HIPAA compliant on its own. These safeguards are designed around HIPAA requirements and support your compliance program; the obligations remain with the practice.
Running on Microsoft Azure.
Microsoft’s HIPAA business associate terms are incorporated into the Microsoft Product Terms and Data Protection Addendum and apply to in-scope Azure services, with documentation available through Microsoft’s Service Trust Portal. Weber Performance Nutrition acts as a business associate to every practice using the platform, and a business associate agreement is available to all customers.
What we are not claiming.
SOC 2 Type II is not complete. It is planned once practitioner revenue supports the audit, and the report will be published when it exists. If your procurement process requires a current Type II report today, we are not yet the right fit — and we would rather say so in the first meeting than the sixth.