Skip to content

HIPAA-COMPLIANT  |  ENCRYPTED DATA  |  CONTROLLED ACCESS

Security & Compliance

Built for the standards required to handle sensitive clinical data in healthcare environments

CPET-Insight is designed with security, privacy, and controlled data handling at its core

Designed for Clinical Workflows

Security, privacy, and reliability are built into the way CPET-Insight handles clinical data

Healthcare workflows

Built for clinics, programs, and healthcare teams that handle sensitive CPET data

Protected data

Designed around controlled access, encrypted handling, and appropriate data-use boundaries

Operational accountability

Supports audit-ready workflows, BAA review, and documented compliance practices

HIPAA-Compliant Data Handling

CPET-Insight is designed to meet HIPAA requirements for the handling, transmission, and storage of protected health information (PHI)

HIPAA

HIPAA-compliant cloud environment

The CPET-Insight platform is hosted within a HIPAA-compliant cloud environment with safeguards that support secure clinical data workflows

BAAs are available for partner organizations - contact [email protected] to initiate a BAA review or request supporting documentation

Key Practices

Secure transmission of patient data

Encryption in transit and at rest

Access controls to limit data visibility

Audit-ready data handling practices

Business Associate Agreements (BAAs) available for partner organizations

Secure Data Infrastructure

Clinical data is processed in a controlled environment built for confidentiality, integrity, and availability

Infrastructure Controls

Protected from submission through report delivery

CPET files, generated reports, and associated records are handled through encrypted systems with access controls, monitoring, and defined operational safeguards

Encryption in Transit

Data transmitted between users and CPET-Insight infrastructure is secured with industry-standard transport-layer encryption

Encryption at Rest

Stored CPET files, reports, and associated records are encrypted at the database and file-storage level

Role-Based Access Controls

Access to patient data and system functions is granted on a least-privilege basis with permissions enforced at the platform level

Continuous System Monitoring

System health, access patterns, and security events are monitored continuously with automated alerting and defined escalation paths

Patient Data Privacy

Patient data is used only for requested CPET interpretation and report generation

Purpose-limited use

Submitted CPET files are used to generate the requested interpretation and report

No secondary use

CPET-Insight does not sell, share, or repurpose patient data for unrelated uses

Account-limited visibility

Data visibility is restricted by account permissions and authorized-user access

Controlled Platform Access

Access is restricted, segmented, and monitored across the CPET workflow

Access Controls

Secure authentication

Account-based access segmentation

Separation of clinic and individual user data

Role-based permissions are enforced at the platform level, with role changes administered and logged

Audit Trail

Platform activity is logged and traceable

Significant platform actions are recorded with timestamp, user identity, and event context for compliance review

  • CPET file submissions
  • Report generation and delivery
  • Report access and download
  • Login, session, and permission changes

How Data Moves Through the Platform

Each step is controlled, monitored, and designed to preserve data integrity

1

File Upload

Secure file submission

2

Secure Processing

Encrypted handling

3

Physiologic Interpretation

Controlled analysis environment

4

Report Delivery

Clinician-reviewed report

5

Controlled Access

Role-based access

Questions About Security, Compliance, or Integration?

Contact our team for a compliance review, BAA inquiry, or integration discussion