Mercy StaffingMercy Staffing|Trust & Compliance Center
Portal Login →
Built to HIPAA Security Rule standards (45 CFR § 164.312)SOC 2 readiness roadmap

HIPAA Technical Safeguards & Security Architecture

Mercy Staffing maintains rigorous administrative, physical, and technical safeguards to protect electronic Protected Health Information (ePHI). This reference matrix documents our platform security architecture, access controls, encryption standards, and compliance protocols for healthcare facility clients, hospital partners, and compliance reviewers. It is informational and is not a certification or third-party audit report.

Technical Safeguards
8 / 8In Place
Database Backups
DailyEncrypted, 14-day retention
Inactivity Timeout
15 MinMobile Guard

Technical Safeguards Matrix (8)

45 CFR § 164.312(a)(1)

Unique User Identification

RequiredLIVE

Assign a unique name and/or number for identifying and tracking user identity.

Every user is assigned an immutable cryptographic User ID. All portal sessions, clinical records, and data access events are strictly attributed to this identity. Anonymous database access is prohibited.

Standard: Role-Based Access Control (RBAC) with granular tenant boundaries.Verified: 2026-08-27
45 CFR § 164.312(a)(2)(i)

Emergency Access Procedure

RequiredLIVE

Establish procedures for obtaining necessary ePHI during an emergency.

Documented supervisory escalation procedures let authorized staff obtain essential records during urgent situations. Access is attributed to the individual user and logged.

Standard: Supervisory escalation procedure with audit logging.Verified: 2026-08-27
45 CFR § 164.312(a)(2)(ii)

Automatic Logoff & Inactivity Protection

AddressableLIVE

Terminate electronic sessions after a predetermined period of inactivity.

Enforces a 10-minute warning modal followed by a hard 15-minute inactivity termination. Evaluates real wall-clock elapsed time across mobile screen locks, backgrounded tabs, and browser restarts. Backstopped by server-enforced session cookie limits.

Standard: 15-Minute Wall-Clock Inactivity Timeout with secure session teardown.Verified: 2026-08-27
45 CFR § 164.312(a)(2)(iv)

Encryption and Decryption (At-Rest)

AddressableLIVE

Implement a mechanism to encrypt and decrypt electronic protected health information.

All database stores, backups, and document storage are encrypted at rest with AES-256 using Google Cloud built-in encryption and managed keys. The portal keeps cached records in browser memory rather than on device storage.

Standard: AES-256 encryption at rest (Google Cloud).Verified: 2026-08-27
45 CFR § 164.312(b)

Audit Controls & Access Telemetry

RequiredLIVE

Hardware, software, and procedural mechanisms that record and examine activity in information systems.

API requests and record changes are logged with the authenticated user ID, organization, UTC timestamp, and a request correlation ID. Client error reports are scrubbed of Social Security numbers and other sensitive values before they are stored.

Standard: User-attributed request and change logging, with redaction in error reports.Verified: 2026-08-27
45 CFR § 164.312(c)(1)

Data Integrity & Tamper-Evident Electronic Signatures

AddressableLIVE

Policies and procedures to protect ePHI from improper alteration or destruction.

Electronic signatures on clinical documentation and timecards record a signature fingerprint, signer identity, IP address, and UTC timestamp to support non-repudiation and help detect alteration.

Standard: Electronic signatures with signer identity, timestamp, and fingerprint.Verified: 2026-08-27
45 CFR § 164.312(d)

Person or Entity Authentication & Session Security

RequiredLIVE

Verify that a person or entity seeking access to ePHI is the one claimed.

Users sign in through Firebase Authentication (hashed passwords or Google sign-in). Active sessions use scoped HttpOnly, SameSite=Strict cookies with a 1-hour ceiling to reduce the risk of token theft.

Standard: Firebase Authentication with secure, short-lived session cookies.Verified: 2026-08-27
45 CFR § 164.312(e)(1)

Transmission Security & In-Transit Encryption

AddressableLIVE

Guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.

All web traffic and service communication is encrypted with TLS (1.2 or higher) over HTTPS. HTTP Strict Transport Security (HSTS, max-age=63072000, preload) and Content Security Policies (CSP) help prevent interception and downgrade attacks.

Standard: HTTPS-only (TLS 1.2+) with HSTS preload.Verified: 2026-08-27

Compliance Protocols & SOC 2 Readiness Roadmap (5)

Current operational controls and audit-readiness roadmap across HIPAA and SOC 2 Trust Services Criteria.

CC6.1, CC6.2, CC6.3 (Access Management)

Identity Verification, Granular RBAC & 2FA

NEXT UP

Enforces least-privilege role boundaries across workers, facility customers, and staff, accompanied by short-lived session cookies and automatic inactivity termination.

Controls Implemented:
  • ✓Unique immutable cryptographic User IDs
  • ✓Granular Role-Based Access Control (RBAC) per tenant
  • ✓15-Minute Wall-Clock Inactivity Timeout (with mobile sleep wake guard)
  • ✓HttpOnly SameSite=Strict secure session cookies (1-hour ceiling)
Roadmap:Multi-Factor Authentication (2FA/MFA via SMS & TOTP Authenticator apps) is next up on the authentication queue.
CC6.6, CC6.7 (Data Protection & Encryption)

At-Rest Encryption & In-Transit TLS

LIVE

Encrypts electronic health records across database stores, backups, and network transmission.

Controls Implemented:
  • ✓AES-256 encryption at rest across all datastores (Google Cloud)
  • ✓Browser cache kept in memory, not on device storage
  • ✓HTTPS-only traffic with TLS 1.2 or higher
  • ✓HSTS headers (max-age=63072000, preload) and Content Security Policies
PI1.1, PI1.2 (System Processing Integrity)

Electronic Signatures & Document Intake Checksums

ROADMAP

Helps ensure patient documentation, orders, and timesheets are not altered or forged after signing.

Controls Implemented:
  • ✓Electronic signatures with signer identity, timestamp, and fingerprint on clinical documentation and timesheets
  • ✓A single controlled write path for record changes
Roadmap:Post-2FA: Automated cryptographic checksum (SHA-256) calculation on clinical file attachments during intake.
CC7.2, CC7.3 (Security Event Monitoring)

Audit Trails & Long-Term Compliance Archival

ROADMAP

Maintains user-attributed audit trails of healthcare data changes, with automatic redaction in error reports.

Controls Implemented:
  • ✓Change logging with user ID, organization ID, UTC timestamp, and request ID
  • ✓Automatic scrubbing of SSNs and other sensitive values in client error reports
Roadmap:Post-2FA: Dedicated 6-year locked compliance archive sink with automated retention lifecycle.
CC7.4, A1.2, CC2.1 (Resiliency & Governance)

Disaster Recovery, BAA Register & Third-Party Audits

ROADMAP

Organizational and operational safeguards for availability, backups, and vendor compliance.

Controls Implemented:
  • ✓Automated daily encrypted database backups, retained for 14 days
  • ✓Regional multi-zone hosting on Google Cloud
  • ✓Automated code-quality and security checks in the build pipeline
Roadmap:Post-2FA: Centralized Business Associate Agreement (BAA) vendor registry and annual third-party penetration testing.

Frequently Asked Questions for Facility Clients & Auditors (5)

Key answers regarding encryption, tenant isolation, session boundaries, and audit logging.

The platform enforces a strict 15-minute inactivity logoff policy. A warning modal appears at 10 minutes of inactivity. When 15 minutes have elapsed without interaction—including when mobile devices are locked or backgrounded—the platform automatically tears down the session, deletes session credentials, clears cached memory, and redirects to the login screen.

Category: Access Control