TRUST CENTER
Healthcare technology earns trust through design, governance, and accountability.
AceHCT designs healthcare solutions with security, privacy, access control, auditability, human oversight, and responsible AI as core requirements. Specific safeguards, certifications, agreements, and deployment responsibilities are documented for each product and client implementation.
SECURITY BY DESIGN
Security and privacy are built into the way solutions are designed and operated.
- Encryption in transit and at rest
- Identity controls, single sign-on, multi-factor authentication, and role-based access
- Least-privilege and minimum-necessary access
- Tenant and client data separation
- Audit logging and traceability of user and automated actions
- Secure software development, testing, and change control
- Vulnerability management, monitoring, incident response, and backup planning
- Data-retention and deletion controls based on contract and workflow
- Secure secrets and service-account management
- Use of approved, contractually appropriate infrastructure and AI services
RESPONSIBLE AI
Practical principles for governed AI.
- Encryption in transit and at rest
- Identity controls, single sign-on, multi-factor authentication, and role-based access
- Least-privilege and minimum-necessary access
- Tenant and client data separation
- Audit logging and traceability of user and automated actions
- Secure software development, testing, and change control
- Vulnerability management, monitoring, incident response, and backup planning
- Data-retention and deletion controls based on contract and workflow
- Secure secrets and service-account management
- Use of approved, contractually appropriate infrastructure and AI services
RESPONSIBLE AI
Practical principles for governed AI.
| Principle | Practical application |
|---|---|
| Purpose limitation | Use AI for defined workflows and outcomes, not unrestricted decision-making. |
| Human oversight | Escalate uncertainty, exceptions, sensitive interactions, and decisions requiring professional judgment. |
| Data minimization | Use only the information required for the approved workflow. |
| Transparency | Define where AI is used, what it can do, and its limitations. |
| Validation | Test workflows, prompts, rules, integrations, and outputs before and after deployment. |
| Monitoring | Review accuracy, exceptions, safety signals, drift, usage, and outcomes. |
| Governed knowledge | Use approved, versioned content and controlled update processes. |
| Accountability | Document responsibilities across AceHCT, the client, cloud/AI vendors, and implementation partners. |
HIPAA
Compliance depends on the complete implementation.
AceHCT solutions are designed to support HIPAA-compliant implementations when configured and operated with the required safeguards, agreements, policies, and approved services. HIPAA compliance is a shared operational responsibility and is not established by software alone.
Compliance
Privacy
Security
TRUST RESOURCES
Information for evaluating security, privacy, and responsible AI.
- Security overview
- Responsible AI statement
- Privacy & data-handling overview
- Subprocessor / third-party service disclosure process
- Business Associate Agreement availability by product and deployment
- Security questionnaire contact
- Incident-reporting / security contact
- • Product-specific technical and compliance documentation available under NDA
