Security & compliance
Built for substance-use privacy from the first schema
42 CFR Part 2 is not a permission flag added late in a product's life. In MIYO it shapes the record model itself: sensitive material is segmented at the data layer and released only against a specific, current, versioned consent.
Compliance at a glance
HIPAA
Administrative, physical, and technical safeguards, with a BAA executed before any client data is loaded.
42 CFR Part 2
Segmented SUD records with consent-gated disclosure and disclosure accounting built into the record model.
Encryption
Data encrypted in transit and at rest, with key management separated from application access.
Audit trail
Every view, change, disclosure, and AI-assisted action timestamped and attributable to an identity.
Consent
Consent is an object, not a checkbox
Part 2 requires that a disclosure be traceable to a specific consent that was valid at the moment it happened. That is only possible if consent is modelled properly.
Versioned
Each consent is a dated version with its own scope, recipient, purpose, and expiry. Superseded versions are retained, not overwritten.
Scoped
Consent names what may be disclosed, to whom, and for what purpose. Requests outside that scope do not return the record.
Revocable
Revocation takes effect immediately across the platform, including for integrations and AI agents already holding a task.
E-signed
Legally binding electronic signature with identity verification and a retained signing record.
Renewal-aware
Approaching expiry generates a staff task and a client notification, so care is never delivered against a lapsed consent.
Accounted for
Every disclosure made under a consent is logged against it, producing the accounting Part 2 requires on request.
Access
People see the record their role permits
Role-based permissions reach down to the field. A biller can see what they need to submit a claim without reading the session content that produced it.
Granular roles
Permissions defined per role and per organization — therapist, prescriber, supervisor, case manager, biller, front desk, owner — rather than a fixed set of tiers.
Tenant isolation
Your practice's data is isolated from every other tenant on shared infrastructure. Configuration, users, forms, and records do not cross the boundary.
Segmented records
Part 2 material is walled off from the general chart. Users without a qualifying consent see that a record exists only where the regulation permits it.
Supervision boundaries
Supervisors see supervisee caseloads for co-signature and review, scoped to the supervisory relationship and its dates.
Platform
Operational security
The practical controls behind the certifications — what actually runs on a Tuesday.
Cloud-native isolation
Containerized workloads on AWS with network segmentation between services and environments.
Backup & recovery
Automated backups with point-in-time recovery and periodically tested restore procedures.
Least privilege
MIYO staff access to production is scoped, approved, time-bound, and logged. Support access requires your authorization.
Monitoring
Continuous monitoring with alerting on anomalous access patterns and failed authentication activity.
Vulnerability management
Dependency scanning, patch cadence, and periodic third-party penetration testing.
Incident response
A documented response and breach-notification procedure with defined timelines and named owners.
Compliance questions
What procurement usually asks
Will you sign a BAA?
Yes, before any client data is loaded. A standard BAA is provided during onboarding and we can review redlines with your counsel.
Where is our data stored?
In AWS regions within the United States. Data does not leave that boundary for processing, including AI processing.
Can we export everything?
Yes, at any time. The complete clinical and financial record exports in standard formats, and export rights survive termination.
How do you handle a Part 2 disclosure request?
Disclosures are logged against the consent that authorized them, so the accounting a client or auditor can request is produced from the record rather than reconstructed by hand.
Do AI features change our compliance posture?
Agents operate under the same role, consent, and segmentation rules as human users, inside the same compliance boundary. Their actions are logged with model version and reviewing user. Clinical content is not used to train foundation models.
Can we get your security documentation?
Yes. Request the security package on the demo form and we'll send the architecture overview, control summary, and the completed vendor questionnaire responses.
