Healthcare software lives or dies on trust. We built Indigo Health so that trust isn't a marketing claim — it's the architecture.
This page is the short version. The full policy library and BAA are available to prospects and customers under NDA, and our team is happy to walk your security and compliance reviewers through any of it.
Indigo Health doesn't practice medicine, doesn't supervise clinicians, and doesn't decide what counts as a medical record. Our customers — the Covered Entities who treat patients — make those decisions, and we process PHI only as their BAA directs.
A single, focused legal role means fewer surprises in your vendor risk review and a cleaner story for your regulators.
The single most important thing about how Indigo Health is built: PHI never lands on laptops, analytics warehouses, or test environments. We call this our minimum-access PHI architecture, and it's not a policy we ask people to follow — it's how the platform is built:
When a vendor is breached, every Covered Entity asks the same question: "How much of our patient data did that vendor have sitting around?" For Indigo Health, the honest answer is: it stayed within production controls, and it was never on anyone's laptop.
The platform runs on Microsoft Azure, on HIPAA-eligible services covered by Microsoft's BAA — inheriting enterprise-grade physical security and the global compliance certifications of one of the most heavily audited cloud platforms in the world. PHI is encrypted in transit and at rest. For email that may touch PHI, we use Paubox for HIPAA-compliant delivery.
We don't ask you to take our infrastructure on faith — we build on a foundation your own auditors have almost certainly assessed before.
Compliance shouldn't be a vibe. Ours is a documented library of policies and procedures, organized to the HIPAA Security Rule, so your reviewers can map our controls to the regulation directly.
Vendor & supply chain — documented subprocessor management; every PHI-handling third party bound by HIPAA-compliant agreements.
This isn't a slide deck. It's a maintained, version-controlled library that our own team operates against every day.
We know what a vendor risk questionnaire looks like.
We've designed our compliance posture so the answers are ready before you ask.
Every control above produces a trail. Activity is captured in tamper-resistant, append-only logs, and governed evidence is retained in a write-once evidence repository built to satisfy a regulator, not just check a box. When a reviewer asks "show me," the answer is documented evidence with a date on it — available for review by customers and regulators.
We notify affected customers of confirmed security incidents involving their PHI in accordance with the executed Business Associate Agreement and HIPAA's Breach Notification Rule. Incident triage, containment, and notification are governed by our Security Incident Response and Breach Notification Policy and the supporting procedures — so the response on the worst day isn't improvised.
Last reviewed: June 2026
Security and compliance reviewers — we'd rather meet you early than late. Reach us at security@indigo.health, or for general inquiries, hello@indigo.health.