EXCEND is launching soon — book a walkthrough for early access.

Security & compliance

Built to support HIPAA compliance.

EXCEND holds protected health information on behalf of the practices that use it. This page states what is implemented, and what is not.

01 — Running today

Implemented and in use.

  • Dedicated PHI access log covering every read and write
  • Strict organization-level data isolation
  • Multi-factor authentication (TOTP) with single-use recovery codes
  • Per-account lockout
  • Session tokens stored hashed
  • Server and client session timeouts
  • Break-glass access requiring written justification, fully logged
  • Right-of-access export
  • Accounting of disclosures
  • Strict Content Security Policy with no inline-script vector
  • Optional HIPAA mode mandating MFA
  • Encryption in transit and at rest

No software makes a practice HIPAA compliant on its own. These safeguards are designed around HIPAA requirements and support your compliance program; the obligations remain with the practice.

02 — Hosting

Running on Microsoft Azure.

Microsoft’s HIPAA business associate terms are incorporated into the Microsoft Product Terms and Data Protection Addendum and apply to in-scope Azure services, with documentation available through Microsoft’s Service Trust Portal. Weber Performance Nutrition acts as a business associate to every practice using the platform, and a business associate agreement is available to all customers.

03 — Not yet

What we are not claiming.

SOC 2 Type II is not complete. It is planned once practitioner revenue supports the audit, and the report will be published when it exists. If your procurement process requires a current Type II report today, we are not yet the right fit — and we would rather say so in the first meeting than the sixth.