Skip to main content

Security at CodePause

Building healthcare technology with security, compliance, and trust at the foundation

Our Security Mission

At CodePause, security isn't an afterthought—it's the foundation of everything we build. From day one, OutsideINsights has been architected with healthcare-grade security standards, recognizing that we handle Protected Health Information (PHI) and sensitive student records that require the highest levels of protection.

Our mission is to build technology that healthcare providers and educational institutions can trust with their most sensitive data. We are committed to continuous improvement, transparency, and accountability in our security practices.

Security Framework

CodePause is building OutsideINsights to meet enterprise-grade security standards from the ground up:

HIPAA Compliant

Our infrastructure and practices are designed to comply with HIPAA Security and Privacy Rules for handling Protected Health Information.

FERPA Compliant

For school deployments, we maintain FERPA protections for student education records and family privacy.

Security by Design

Every feature is developed with security best practices from initial architecture through deployment.

Data Encryption

Encryption in Transit

All data transmitted between users and our servers is encrypted using industry-standard protocols:

  • TLS 1.2+: Transport Layer Security with strong cipher suites for all web and API traffic
  • Perfect Forward Secrecy: Session keys that cannot be compromised even if long-term keys are exposed
  • Certificate Validation: Valid SSL/TLS certificates from trusted certificate authorities
  • HSTS Enforcement: HTTP Strict Transport Security to prevent downgrade attacks

Encryption at Rest

All sensitive data stored in our systems is encrypted at rest:

  • AES-256 Encryption: Industry-standard encryption for all databases and file storage
  • Encrypted Backups: All backup data is encrypted using the same standards as production data
  • Key Management: Encryption keys are managed separately from encrypted data with secure key rotation practices
  • Hardware Encryption: Database and storage volumes utilize hardware-level encryption where available

Access Controls & Authentication

Multi-Factor Authentication (MFA)

OutsideINsights is framed to support multi-factor authentication for all user accounts, adding an essential second layer of security beyond passwords. MFA options are designed to include:

  • Time-based One-Time Passwords (TOTP) via authenticator apps
  • SMS-based verification codes
  • Email-based verification codes
  • Organization-specific authentication requirements

Role-Based Access Control (RBAC)

Our platform implements granular role-based access controls to ensure users only access data necessary for their role:

  • Least Privilege Principle: Users are granted the minimum access required for their responsibilities
  • Granular Permissions: Fine-grained control over who can view, edit, create, or delete specific data
  • Patient Authorization: Third-party observers can only access data for patients who explicitly authorize them
  • Audit Trails: All access attempts and data modifications are logged for security review

Session Management

  • Automatic session timeouts for inactive users
  • Secure session token generation and validation
  • Immediate session invalidation upon logout
  • Device and location tracking for suspicious activity detection

Infrastructure Security

HIPAA-Compliant Hosting

OutsideINsights is being migrated to HIPAA-compliant enterprise infrastructure designed specifically for healthcare applications:

  • Cloud infrastructure providers with HIPAA Business Associate Agreements
  • Dedicated, isolated environments for PHI processing
  • Geographic redundancy and disaster recovery capabilities
  • 99.9%+ uptime SLA for production systems

Network Security

  • Firewalls: Network-level firewalls with strict ingress/egress rules
  • DDoS Protection: Distributed denial-of-service attack mitigation
  • Intrusion Detection: Continuous monitoring for suspicious network activity
  • Private Networking: Internal services communicate over private networks
  • VPN Access: Secure VPN required for administrative access to infrastructure

Vulnerability Management

  • Regular security scanning for vulnerabilities
  • Automated patch management for operating systems and dependencies
  • Penetration testing planned prior to production launch
  • Vulnerability disclosure program for responsible reporting

Application Security

Secure Development Practices

Our development process incorporates security at every stage:

  • Security Training: All developers receive security awareness training
  • Code Review: Peer review of all code changes with security considerations
  • Secure Coding Standards: Following OWASP guidelines and industry best practices
  • Dependency Scanning: Automated scanning for vulnerabilities in third-party libraries
  • Static Analysis: Automated code analysis to detect security issues before deployment

Protection Against Common Threats

OutsideINsights is designed with protections against common web application vulnerabilities:

  • SQL Injection: Parameterized queries and ORM protections
  • Cross-Site Scripting (XSS): Input validation and output encoding
  • Cross-Site Request Forgery (CSRF): Token-based CSRF protection
  • Clickjacking: X-Frame-Options and Content Security Policy headers
  • Authentication Attacks: Rate limiting, account lockout, and password strength requirements

Monitoring, Logging & Auditing

Comprehensive Audit Logs

Our platform maintains detailed audit logs as required by HIPAA and best practices:

  • User authentication attempts (successful and failed)
  • Data access, viewing, modification, and deletion
  • Administrative actions and configuration changes
  • System events and errors
  • Timestamp, user identity, and IP address for all logged events

Security Monitoring

  • Real-Time Alerts: Automated alerts for suspicious activity or security events
  • Log Analysis: Regular review of security logs for anomalies
  • Performance Monitoring: System health and availability tracking
  • Incident Response: Documented procedures for security incident handling

Audit Trail Retention

Audit logs are retained for a minimum of 6 years to meet HIPAA requirements and support forensic investigations if needed. Logs are stored securely with the same encryption and access controls as production data.

HIPAA Business Associate Agreements (BAA)

For healthcare providers who are HIPAA-covered entities, CodePause acts as a Business Associate. We execute Business Associate Agreements (BAAs) that outline:

  • Permitted Uses: How we may use and disclose Protected Health Information (PHI)
  • Safeguards: Our obligations to implement appropriate administrative, physical, and technical safeguards
  • Subcontractors: Requirements that any subcontractors handling PHI also comply with HIPAA
  • Breach Notification: Our commitment to report any security incidents or breaches
  • Access Rights: Individual rights to access, amend, and receive an accounting of PHI disclosures
  • Termination: Procedures for returning or destroying PHI upon contract termination

BAAs are executed as part of the customer onboarding process. To request a BAA, contact us at legal@codepause.com.

Data Backup & Disaster Recovery

Automated Backups

Our infrastructure is designed to ensure data durability and availability:

  • Continuous automated backups of all production databases
  • Point-in-time recovery capabilities
  • Encrypted backup storage in geographically distributed locations
  • Regular backup restoration testing to verify integrity

Business Continuity

  • Redundancy: Redundant systems and data replication across availability zones
  • Failover: Automated failover to backup systems in case of primary system failure
  • Recovery Time: Target of 4-hour recovery time objective (RTO) for critical systems
  • Recovery Point: Target of 1-hour recovery point objective (RPO) for data loss minimization

Employee Access & Training

Access Controls

  • Strict need-to-know access policies for all team members
  • Multi-factor authentication required for all employee accounts
  • Regular access reviews and immediate revocation upon role change or departure
  • Separate development, staging, and production environments
  • All production access logged and monitored

Security Training

  • Mandatory HIPAA and security awareness training for all employees
  • Role-specific training for developers and operations staff
  • Annual refresher training and updates on new threats
  • Phishing awareness and social engineering prevention

Background Checks

All employees with access to PHI undergo background checks as part of the hiring process, in compliance with HIPAA workforce security requirements.

Incident Response & Breach Notification

Incident Response Plan

We maintain a documented incident response plan that includes:

  • Procedures for detecting, reporting, and responding to security incidents
  • Designated incident response team and escalation procedures
  • Containment, eradication, and recovery processes
  • Post-incident analysis and lessons learned
  • Communication protocols with affected parties

Breach Notification

In the event of a security incident involving PHI, we will:

  • Notify affected customers without unreasonable delay and no later than 60 days after discovery
  • Provide information about the nature of the breach, the PHI involved, and steps being taken
  • Comply with all HIPAA breach notification requirements
  • Cooperate with customers in their notification obligations to affected individuals
  • Work to prevent similar incidents in the future

Third-Party Vendor Security

We carefully vet all third-party vendors and service providers who may access or process sensitive data:

  • Security assessments and due diligence before vendor engagement
  • Business Associate Agreements with all vendors handling PHI
  • Data Processing Agreements for FERPA-protected student data
  • Regular vendor security reviews and compliance verification
  • Contractual obligations for security standards and breach notification
  • Minimum necessary access principle applied to all vendor integrations

Data Privacy & Retention

Privacy by Design

Privacy is integrated into every aspect of OutsideINsights. We collect only the minimum data necessary for the Services, use it only for authorized purposes, and provide transparency and control to users.

Data Retention

We retain data in accordance with legal and regulatory requirements:

  • PHI: Retained for 6 years from creation or last use (HIPAA requirement)
  • Billing records: Retained for 7 years (IRS requirement)
  • Audit logs: Retained for 6 years minimum
  • Upon request, customer data can be exported or deleted in accordance with applicable regulations

Data Deletion

When data is no longer needed or upon customer request (subject to legal retention requirements), we securely delete it using industry-standard methods to ensure it cannot be recovered.

Compliance & Certifications

Current Compliance Status

HIPAA

Infrastructure and practices designed to comply with HIPAA Security and Privacy Rules

FERPA

Protections for student education records in school deployments

Ongoing Commitment

As OutsideINsights scales toward production launch, we are committed to pursuing formal third-party security certifications and maintaining continuous compliance with all applicable regulations. Our security posture evolves with emerging threats and industry best practices.

Responsible Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to us privately so we can address it promptly:

Security Contact:

Email: security@codepause.com

Please include details about the vulnerability, steps to reproduce it, and any potential impact. We commit to acknowledging reports within 48 hours and working to resolve issues promptly.

Questions About Our Security?

We believe in transparency and are happy to answer questions about our security practices. For security inquiries, compliance documentation, or to request a BAA:

CodePause Inc.

Security Team: security@codepause.com

Legal/Compliance: legal@codepause.com

General Inquiries: info@codepause.com

Phone: 1-202-459-9156

For detailed information about how we collect, use, and protect your personal information, please review our Privacy Policy.