Allia Health uses multiple layers of security to protect the confidentiality, integrity, and availability of clinical data. Cryptographic controls, network isolation, and monitoring help reduce unauthorized access.
Encryption and session security
Allia uses standard cryptographic protocols to protect data throughout its lifecycle.
Encryption: All Protected Health Information (PHI) is encrypted at rest and in transit using AES-256-bit encryption.
Session management: Authentication creates unique session keys that rotate frequently. This reduces the window for potential unauthorized access.
Database environment: Allia Health uses enterprise-grade cloud environments on Amazon Web Services (AWS). Data layers are managed through MongoDB Atlas and PostgreSQL on RDS.
Network isolation and access control
System access follows the principle of least privilege and uses strict perimeter defenses.
Network perimeter: Services are hosted in private networks and isolated through firewalls and granular security groups to prevent unauthorized external access.
Role-based access control (RBAC): A strict identity management framework limits administrative and system access. Personnel can access only the resources required for their specific function.
Audit logging: The system maintains immutable audit trails. Every access event and data change is logged to provide a transparent history of system activity.
Operational security and monitoring
Continuous verification helps identify and address potential risks.
Infrastructure monitoring: Automated systems monitor network traffic and system health 24 hours a day, 7 days a week to detect unusual behavior.
Vulnerability management: Allia Health performs regular automated vulnerability scans and periodic security testing to protect the software stack and underlying infrastructure.
Get help
For technical security questions, contact support@allia.health.
