Security & Compliance
Your data security and patient privacy are core to how we operate. We follow strict security and compliance standards to safeguard every piece of information entrusted to us.

SOC 2 Type II Certified

HIPAA Compliant
SOC 2 Type II
NY Best Medical has completed a SOC 2 Type II audit, demonstrating our commitment to the five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Our audit was conducted by Johanson Group LLP, an independent third-party auditing firm.
HIPAA Compliant
We comply with the HIPAA Privacy Rule and Security Rule, ensuring that all Protected Health Information (PHI) is handled with the highest level of care. Our safeguards include:
- Strict access controls and role-based permissions
- End-to-end encryption of sensitive data
- Secure storage and transmission protocols
- Continuous monitoring and audit logging
- Regular employee training on privacy and security
- Incident response procedures
- Business Associate Agreements (BAAs) with all vendors
What is Protected Health Information (PHI)?
PHI includes any individually identifiable health information that is created, received, maintained, or transmitted by a covered entity. This may include:
- Medical history, diagnoses, and treatment plans
- Appointment and scheduling records
- Insurance and billing information
- Contact information (name, address, phone, email) when linked to health records
- Lab results and imaging studies
How We Protect Your Data
We employ a layered approach to data protection, combining technical, administrative, and physical safeguards.
Technical Safeguards
- Data encryption at rest and in transit (AES-256 / TLS 1.2+)
- Role-based access control (RBAC) with the principle of least privilege
- Network firewalls and intrusion detection systems
- Cloud infrastructure with enterprise-grade security certifications
- Continuous monitoring, alerting, and automated threat detection
- Regular penetration testing and vulnerability assessments
Administrative Safeguards
- Annual security awareness training for all employees
- Documented access policies and procedures
- Vendor risk management and due diligence
- Regular internal and external audits
- Data retention and disposal policies
Physical Safeguards
- Secure facilities with restricted physical access
- Controlled access to workstations and devices containing PHI
- Proper disposal of physical media and documents containing sensitive data
Infrastructure & Availability
Our infrastructure is designed for high availability and resilience. We use redundant, geographically distributed systems to ensure that our services remain available even in the event of localized failures. Continuous monitoring and automated failover mechanisms help maintain uptime and data integrity at all times.
Application & Access Security
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.
- Secure coding: Our development team follows secure coding practices and industry standards (OWASP Top 10) to minimize vulnerabilities.
- Security testing: Applications undergo regular security testing, including static analysis, dynamic analysis, and third-party penetration testing.
- Role-based access control: Access to systems and data is granted on a need-to-know basis, following the principle of least privilege.
- Audit logging: All access to sensitive systems and data is logged and monitored for unauthorized activity.
Patient Rights Under HIPAA
Under HIPAA, you have the following rights regarding your Protected Health Information:
- Right to access: You may request access to your PHI that we maintain.
- Right to request corrections: You may request corrections to your PHI if you believe it is inaccurate or incomplete.
- Right to request restrictions: You may request restrictions on how we use or disclose your PHI.
- Right to an accounting of disclosures: You may request a list of certain disclosures we have made of your PHI.
- Right to confidential communications: You may request that we communicate with you about your health information in a specific way or at a specific location.
- Right to file a complaint: If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services.
To exercise any of these rights, or if you have questions about our security and compliance practices, please contact us at security@nybestmedical.com
NY Best Medical is committed to maintaining the highest standards of data security and patient privacy. We continuously evaluate and improve our security practices to protect your information and ensure compliance with all applicable regulations.