Built for data that carries real clinical stakes.
Keel handles protected health information from day one. Our security posture is built around HIPAA's requirements, not bolted on after the fact.
BAA available for all customer agreements
Audit in progress — report expected Q1 2027
In transit (TLS 1.2+) and at rest (AES-256)
Role-based, scoped to job function
Security principles, applied end to end.
All data encrypted in transit with TLS 1.2+ and at rest with AES-256. Encryption keys are managed and rotated through a dedicated KMS.
SSO/SAML for customer organizations, mandatory MFA for internal access, and role-based permissions scoped to job function.
Every view, decision, and data access is logged with actor, timestamp, and reason — available for customer compliance review.
Customer data is logically isolated per tenant, with segregated environments for production, staging, and analytics.
Internal access to identifiable patient data is scoped and time-limited, following HIPAA's minimum-necessary standard.
Infrastructure and application layers are monitored 24/7 with automated alerting on anomalous access patterns.
From ingestion to deletion, on your terms.
Data arrives via encrypted, authenticated feeds (SFTP, API, or direct payer/PBM integration) into an isolated intake layer.
Signals are normalized and scored within a private VPC. No patient-identifiable data leaves the processing boundary.
Pharmacists access only the patients assigned to their program, through authenticated, audited sessions.
Data is retained per your program's contractual and regulatory requirements, with configurable deletion on request.
Security isn’t only about infrastructure.
Because Keel keeps a licensed clinician in the loop for every recommendation, there’s no autonomous system making unreviewed changes to a patient’s care. That’s a governance safeguard as much as it is a product decision — every action against a patient record is attributable to a specific person, with a documented rationale.
- Every intervention decision is logged with actor, timestamp, and rationale
- Configurable approval workflows per program and therapeutic area
- Customer-controlled data retention and deletion policies
- Business Associate Agreements executed with every customer
We share our security whitepaper, sub-processor list, and sample BAA directly with prospective customers under NDA. Reach out and we’ll get it to your security team same-day.
security@keelhealth.example →See the queue your team would be working today.
Walk through a live risk queue and a full patient review, with the same explainable risk scoring your team would work from.