Sign-in by Microsoft Entra
Authentication is handled by Microsoft Entra External ID, which supports multi-factor authentication. Sign-in runs server-side (Authorization Code + PKCE), so access tokens never reach the browser.
Protecting your family's health information is the entire point. Here is how HealthVault365 keeps it safe.
Encrypted in transit and at rest
Granular, per-record access control
Yours to delete, anytime
How we protect your data
Every measure below is built into the product today: identity, encryption, access control, and privacy by design.
Authentication is handled by Microsoft Entra External ID, which supports multi-factor authentication. Sign-in runs server-side (Authorization Code + PKCE), so access tokens never reach the browser.
Your documents and records are encrypted in transit with TLS and at rest on Microsoft Azure.
Access is enforced on every request. Only the people you explicitly grant can read, update, or delete each individual record.
Files are served through short-lived, scoped links signed with a user-delegation key and managed identity. There are no shared account keys, and links expire quickly.
Logs and diagnostics never contain health information, only opaque identifiers. Protected health data is kept out of telemetry.
Delete your account and everything associated with it at any time. When it is gone, it is gone.
Built on Microsoft's enterprise cloud, with identity, encryption, and isolation as the foundation.
The systems that hold your records are not exposed to the public internet. Services reach them only over a private network, behind isolation that blocks direct outside access.
Protected health information is handled with safeguards designed around HIPAA requirements.
Still have questions?
See the answers to common questions, or reach out and we will reply within one business day.