Skip to content

Security

Protecting your family's health information is the entire point. Here is how HealthVault365 keeps it safe.

Encrypted in transit and at rest

Granular, per-record access control

Yours to delete, anytime

How we protect your data

Security is the foundation, not an add-on

Every measure below is built into the product today: identity, encryption, access control, and privacy by design.

Sign-in by Microsoft Entra

Authentication is handled by Microsoft Entra External ID, which supports multi-factor authentication. Sign-in runs server-side (Authorization Code + PKCE), so access tokens never reach the browser.

Encrypted storage and transport

Your documents and records are encrypted in transit with TLS and at rest on Microsoft Azure.

Per-record permissions

Access is enforced on every request. Only the people you explicitly grant can read, update, or delete each individual record.

Least-privilege file access

Files are served through short-lived, scoped links signed with a user-delegation key and managed identity. There are no shared account keys, and links expire quickly.

Privacy-safe by design

Logs and diagnostics never contain health information, only opaque identifiers. Protected health data is kept out of telemetry.

Your data, your control

Delete your account and everything associated with it at any time. When it is gone, it is gone.

Runs on Microsoft Azure

Built on Microsoft's enterprise cloud, with identity, encryption, and isolation as the foundation.

Private by network design

The systems that hold your records are not exposed to the public internet. Services reach them only over a private network, behind isolation that blocks direct outside access.

HIPAA-aligned architecture

Protected health information is handled with safeguards designed around HIPAA requirements.

Still have questions?

We are happy to walk you through it

See the answers to common questions, or reach out and we will reply within one business day.