HIPAA Technical Safeguards & Security Architecture
Mercy Staffing maintains rigorous administrative, physical, and technical safeguards to protect electronic Protected Health Information (ePHI). This reference matrix documents our platform security architecture, access controls, encryption standards, and compliance protocols for healthcare facility clients, hospital partners, and compliance reviewers. It is informational and is not a certification or third-party audit report.
Technical Safeguards Matrix (8)
Unique User Identification
Assign a unique name and/or number for identifying and tracking user identity.
Every user is assigned an immutable cryptographic User ID. All portal sessions, clinical records, and data access events are strictly attributed to this identity. Anonymous database access is prohibited.
Emergency Access Procedure
Establish procedures for obtaining necessary ePHI during an emergency.
Documented supervisory escalation procedures let authorized staff obtain essential records during urgent situations. Access is attributed to the individual user and logged.
Automatic Logoff & Inactivity Protection
Terminate electronic sessions after a predetermined period of inactivity.
Enforces a 10-minute warning modal followed by a hard 15-minute inactivity termination. Evaluates real wall-clock elapsed time across mobile screen locks, backgrounded tabs, and browser restarts. Backstopped by server-enforced session cookie limits.
Encryption and Decryption (At-Rest)
Implement a mechanism to encrypt and decrypt electronic protected health information.
All database stores, backups, and document storage are encrypted at rest with AES-256 using Google Cloud built-in encryption and managed keys. The portal keeps cached records in browser memory rather than on device storage.
Audit Controls & Access Telemetry
Hardware, software, and procedural mechanisms that record and examine activity in information systems.
API requests and record changes are logged with the authenticated user ID, organization, UTC timestamp, and a request correlation ID. Client error reports are scrubbed of Social Security numbers and other sensitive values before they are stored.
Data Integrity & Tamper-Evident Electronic Signatures
Policies and procedures to protect ePHI from improper alteration or destruction.
Electronic signatures on clinical documentation and timecards record a signature fingerprint, signer identity, IP address, and UTC timestamp to support non-repudiation and help detect alteration.
Person or Entity Authentication & Session Security
Verify that a person or entity seeking access to ePHI is the one claimed.
Users sign in through Firebase Authentication (hashed passwords or Google sign-in). Active sessions use scoped HttpOnly, SameSite=Strict cookies with a 1-hour ceiling to reduce the risk of token theft.
Transmission Security & In-Transit Encryption
Guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.
All web traffic and service communication is encrypted with TLS (1.2 or higher) over HTTPS. HTTP Strict Transport Security (HSTS, max-age=63072000, preload) and Content Security Policies (CSP) help prevent interception and downgrade attacks.
Compliance Protocols & SOC 2 Readiness Roadmap (5)
Current operational controls and audit-readiness roadmap across HIPAA and SOC 2 Trust Services Criteria.
Identity Verification, Granular RBAC & 2FA
Enforces least-privilege role boundaries across workers, facility customers, and staff, accompanied by short-lived session cookies and automatic inactivity termination.
- ✓Unique immutable cryptographic User IDs
- ✓Granular Role-Based Access Control (RBAC) per tenant
- ✓15-Minute Wall-Clock Inactivity Timeout (with mobile sleep wake guard)
- ✓HttpOnly SameSite=Strict secure session cookies (1-hour ceiling)
At-Rest Encryption & In-Transit TLS
Encrypts electronic health records across database stores, backups, and network transmission.
- ✓AES-256 encryption at rest across all datastores (Google Cloud)
- ✓Browser cache kept in memory, not on device storage
- ✓HTTPS-only traffic with TLS 1.2 or higher
- ✓HSTS headers (max-age=63072000, preload) and Content Security Policies
Electronic Signatures & Document Intake Checksums
Helps ensure patient documentation, orders, and timesheets are not altered or forged after signing.
- ✓Electronic signatures with signer identity, timestamp, and fingerprint on clinical documentation and timesheets
- ✓A single controlled write path for record changes
Audit Trails & Long-Term Compliance Archival
Maintains user-attributed audit trails of healthcare data changes, with automatic redaction in error reports.
- ✓Change logging with user ID, organization ID, UTC timestamp, and request ID
- ✓Automatic scrubbing of SSNs and other sensitive values in client error reports
Disaster Recovery, BAA Register & Third-Party Audits
Organizational and operational safeguards for availability, backups, and vendor compliance.
- ✓Automated daily encrypted database backups, retained for 14 days
- ✓Regional multi-zone hosting on Google Cloud
- ✓Automated code-quality and security checks in the build pipeline
Frequently Asked Questions for Facility Clients & Auditors (5)
Key answers regarding encryption, tenant isolation, session boundaries, and audit logging.
The platform enforces a strict 15-minute inactivity logoff policy. A warning modal appears at 10 minutes of inactivity. When 15 minutes have elapsed without interaction—including when mobile devices are locked or backgrounded—the platform automatically tears down the session, deletes session credentials, clears cached memory, and redirects to the login screen.