Security & compliance

Built for data that carries real clinical stakes.

Keel handles protected health information from day one. Our security posture is built around HIPAA's requirements, not bolted on after the fact.

HIPAA-aligned

BAA available for all customer agreements

SOC 2 Type II

Audit in progress — report expected Q1 2027

Data encrypted

In transit (TLS 1.2+) and at rest (AES-256)

Least-privilege access

Role-based, scoped to job function

How we protect data

Security principles, applied end to end.

Encryption everywhere

All data encrypted in transit with TLS 1.2+ and at rest with AES-256. Encryption keys are managed and rotated through a dedicated KMS.

Identity & access control

SSO/SAML for customer organizations, mandatory MFA for internal access, and role-based permissions scoped to job function.

Full audit trail

Every view, decision, and data access is logged with actor, timestamp, and reason — available for customer compliance review.

Isolated environments

Customer data is logically isolated per tenant, with segregated environments for production, staging, and analytics.

Minimum necessary access

Internal access to identifiable patient data is scoped and time-limited, following HIPAA's minimum-necessary standard.

Continuous monitoring

Infrastructure and application layers are monitored 24/7 with automated alerting on anomalous access patterns.

Data lifecycle

From ingestion to deletion, on your terms.

01
Ingestion

Data arrives via encrypted, authenticated feeds (SFTP, API, or direct payer/PBM integration) into an isolated intake layer.

02
Processing

Signals are normalized and scored within a private VPC. No patient-identifiable data leaves the processing boundary.

03
Review

Pharmacists access only the patients assigned to their program, through authenticated, audited sessions.

04
Retention & deletion

Data is retained per your program's contractual and regulatory requirements, with configurable deletion on request.

Clinical governance

Security isn’t only about infrastructure.

Because Keel keeps a licensed clinician in the loop for every recommendation, there’s no autonomous system making unreviewed changes to a patient’s care. That’s a governance safeguard as much as it is a product decision — every action against a patient record is attributable to a specific person, with a documented rationale.

  • Every intervention decision is logged with actor, timestamp, and rationale
  • Configurable approval workflows per program and therapeutic area
  • Customer-controlled data retention and deletion policies
  • Business Associate Agreements executed with every customer
Request our security documentation

We share our security whitepaper, sub-processor list, and sample BAA directly with prospective customers under NDA. Reach out and we’ll get it to your security team same-day.

security@keelhealth.example →

See the queue your team would be working today.

Walk through a live risk queue and a full patient review, with the same explainable risk scoring your team would work from.