Security and HIPAA

Trust is part of
the care infrastructure.

WellReady is built and operated for HIPAA-compliant handling of protected health information and personally identifiable information across behavioral health, recovery housing, treatment court, and community programs.

HIPAACompliant operationsAzureProduction data hostingEncryptedAt rest and in transitRole-awareMinimum necessary access

Security by responsibility

Compliance is more than a hosting provider.

HIPAA requires administrative, physical, and technical safeguards to work together. WellReady pairs the protected foundation of Microsoft Azure with application controls, operating practices, and role-aware workflows designed around sensitive behavioral health information.

This public overview explains the control model without publishing sensitive configuration details. Deeper architecture, implementation evidence, and organization-specific responsibilities can be addressed during a formal security review.

HIPAA safeguard framework

Three layers, one operating model.

01

Administrative safeguards

Access is provisioned around job responsibility and the minimum information necessary. Operational practices address account management, workforce access, change control, incident handling, and ongoing review.

02

Technical safeguards

Unique user access, role-based permissions, tenant boundaries, encrypted data handling, session controls, and traceable activity help protect the confidentiality and integrity of electronic PHI.

03

Cloud and physical safeguards

Production data and services are hosted on Microsoft Azure. Azure provides the protected physical and cloud foundation, while WellReady manages application, tenant, identity, and operational controls above it.

Control areas

Protection across identity, data, and operations.

Controls are layered so no single setting carries the full responsibility for protecting sensitive records.

01

Identity and access

Unique accounts and role-specific permissions support least-privilege access across administrative, clinical, operational, peer, billing, and court functions.

02

Tenant separation

Each organization’s production environment is separated around its users, programs, configuration, and records to reduce unintended cross-tenant exposure.

03

Encryption

PHI and PII are protected through encrypted transport and encrypted storage within the production environment.

04

Auditability

Security-relevant and record-level activity is designed to remain attributable so organizations can review who did what and when.

05

Availability and recovery

Managed continuity, backup, and recovery practices are incorporated into production operations to support restoration after an interruption.

06

Change and vulnerability management

Production changes are controlled, reviewed, and validated. Security findings are assessed, prioritized, remediated, and retested according to risk.

Data lifecycle

Protected from collection through removal.

Security decisions follow the information throughout its lifecycle, not only while it is sitting in a database.

01

Collect

Capture only the information needed for authorized care, housing, program, billing, and reporting workflows.

02

Store

Keep production PHI and PII within the protected Azure-hosted environment and its controlled services.

03

Use

Apply role and tenant boundaries so information is available to the right people for the right purpose.

04

Share

Use deliberate releases, permissions, and workflow-specific views instead of broad record exposure.

05

Retain and remove

Align retention, export, and deletion decisions with organizational requirements, applicable agreements, and legal obligations.

Testing and assurance

Test deliberately. Learn measurably.

WellReady supports coordinated non-destructive and destructive security validation in an authorized, isolated environment using fictional data. Destructive testing should not be performed against a live production tenant or any environment containing real PHI.

Define scope

Identify the environment, accounts, systems, test cases, time window, and stop conditions before testing begins.

Protect people and data

Use synthetic records, dedicated test identities, and an isolated tenant with no connection to real client information.

Preserve evidence

Record expected results, timestamps, logs, observed behavior, impact, and restoration outcomes for each test.

Recover and retest

Confirm restoration, remediate findings by risk, and repeat the relevant test to verify the control now behaves as intended.

Shared responsibility

Secure software and secure use belong together.

WellReady provides the protected application and production operating environment. Each customer remains responsible for appropriate user access, workforce policies, endpoint and device security, data-entry practices, and the way its organization fulfills its own HIPAA obligations.

Discuss your security requirements