Home Platform Soro Data Patient portal The app (soon) Solutions For teams For patients Open it Soro Data ↗ Capabilities Bill audit Hospital rates Payer rates Security Company Pricing Resources About Contact Log in Get started
Security

Your health data deserves a vault. So we built one.

Security is not an add-on at Soro, it is how we operate. Six locks stand between your medical records and the outside world. Scroll through each one.

Follow your data
Lock 01 · HIPAA & BAAs

Every hand signs first

Soro operates under signed HIPAA Business Associate Agreements with every vendor that touches health data. Nobody in our supply chain sees your records without being legally bound the same way we are.

How we use and protect your information is spelled out in our privacy policy.

Handshake HIPAA review BAA signed Access opens
Lock 02 · Encryption

Encrypted in transit and at rest

Data moves over TLS and rests under AES-256, backups included. There is no unencrypted path in and no unencrypted copy inside.

Plain data TLS handshake AES-256 cipher Encrypted at rest
Lock 03 · Secure intake

One door in, straight to storage

Billing files upload through an encrypted channel that lands them directly in secured storage. They are never emailed and never handled as loose files.

File upload Encrypted channel Secured storage Verified landing
Lock 04 · Access controls

Least privilege, fully logged

People see only what their work requires, behind individual authenticated logins. Every access to health data is logged: who, what, when. Everybody who can touch PHI is certified to handle it.

Authenticated login Certified staff Scoped access Logged read
Lock 05 · Infrastructure

An isolated home on HIPAA-eligible cloud

Your records live on HIPAA-eligible cloud infrastructure, inside an isolated network environment. Nothing sits on a laptop, a phone, or a thumb drive.

HIPAA-eligible cloud Isolated network No local copies Monitored boundary
Lock 06 · Monitoring

Watched around the clock

Logging and monitoring run continuously. Unusual access gets flagged and reviewed the moment it appears, not discovered later.

Continuous scan Anomaly flagged Human review Resolved
The short version

Security by the numbers

0 bit AES encryption On every stored byte, backups included
0 of vendors that touch health data under signed BAAs Before any health data moves
0 logging and monitoring No off hours, no blind spots
0 files outside secured storage Never emailed, never loose
Follow one file

What happens to your bill at Soro

From the moment it leaves your system to the moment someone reads it, a file is never unprotected and never unaccounted for.

Upload

The file leaves your system through an encrypted link. Nothing travels by email.

In transit

TLS wraps it the whole way. No readable copy exists en route.

At rest

It lands in secured storage and rests under AES-256, isolated from the open internet.

On the record

Every open and every read is logged with a name and a time. Nothing happens quietly.

The rules we run on

Always and never

Four promises we keep, four lines we do not cross.

We always

  • Sign the agreement before any data moves
  • Encrypt every byte, in transit and at rest
  • Scope access to exactly what the job requires
  • Watch the logs around the clock

We never

  • Email your bills or records around as loose attachments
  • Store your records on laptops or portable media
  • Give a vendor access before a HIPAA agreement is signed
  • Let anyone touch your health data without it being logged
Questions

Ask us directly

If you want to know exactly how your records are handled, ask. Reach us through the contact page and you will get a direct answer from a person.