OrthoHuddle envelope encryption flow An animated timeline showing patient data being encrypted with a data encryption key, the key being wrapped by a protected key encryption key, ciphertext being stored, and authorised access being audited. OrthoHuddle Security: sealed clinical data, accountable access patient data intake DEK generated data encryption key DEK ready data encrypted payload becomes ciphertext ciphertext created DEK wrapped KEK remains protected in vault wrapped key ready ciphertext stored ciphertext + wrapped DEK authorised service decrypts unwrap DEK, decrypt in session audit access event retained

Security Overview

At OrthoHuddle, the security of patient data, care team professional information and clinical workflows is a top priority. We're committed to applying industry-leading practices, transparent processes and continuous improvement to earn and maintain your trust.

Secure Connections

All communications are encrypted in transit using TLS 1.2 or higher with strong authentication and session management.

Learn more
Data At Rest & Storage

Envelope encryption (AES-256-GCM) for all sensitive data with secure infrastructure hosted in compliant facilities.

Learn more
Access Control & Identity

Least privilege principles, role-based access control, and multi-factor authentication for high-privilege accounts.

Learn more
Network Segmentation

VPNs, VPCs, firewalls, and intrusion detection systems to isolate sensitive workloads and minimize attack surface.

Learn more
Monitoring & Logging

Comprehensive audit logs, SIEM integration, and formal incident response procedures.

Learn more
Vulnerability Management

Regular scanning, annual penetration testing, and systematic patching of all systems.

Learn more
Data Retention & Backups

Secure backups with geographic separation, retention policies, and verified deletion protocols.

Learn more
Compliance & Standards

Aligned with ISO 27001, ISO 27701, SOC 2, and Australian Privacy Act requirements.

Learn more
Third-Party Risk

Rigorous vendor evaluation, Data Processing Agreements, and ongoing monitoring of supply chain.

Learn more
Responsible Disclosure

Clear process for security researchers to report vulnerabilities responsibly.

Learn more
Security FAQ

Answers to common questions about data storage, access, breaches, and deletion requests.

Learn more
Continuous Improvement

Our ongoing commitment to training, process improvement, and staying ahead of threats.

Learn more

Have questions about security?

If you have any questions about security at OrthoHuddle, or wish for a deeper dive into any element of our controls, please don't hesitate to reach out.

Contact our security team