Skip to content

Security & Compliance

Quilted EHR is built to meet HIPAA requirements for protected health information (PHI).

  • Business Associate Agreement (BAA) — Signed automatically at account creation. Download a copy from Admin > Compliance > BAA.
  • Encryption — All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Data centers — US-based, SOC 2 Type II certified infrastructure.

MFA is required for all users and cannot be disabled:

  • Authenticator app — Google Authenticator, Authy, 1Password, etc. (recommended)
  • SMS — Available as a fallback.
  • Hardware key — WebAuthn / FIDO2 for high-security environments.

Users set up MFA during first login. Admins can reset a user’s MFA from User Management.

SAML 2.0 SSO is available on Professional and Enterprise plans. Configure from Admin > SSO with:

  • Identity provider (Okta, Azure AD, Google Workspace, etc.)
  • Metadata URL or XML upload
  • Attribute mapping for name and email

Every action that creates, views, modifies, or deletes PHI is logged:

  • User, timestamp, IP address, and action
  • Affected patient and data type
  • Before/after values for edits

View from Admin > Audit Log. Logs are retained for 7 years and exportable as CSV.

EPCS (Electronic Prescribing of Controlled Substances)

Section titled “EPCS (Electronic Prescribing of Controlled Substances)”

Prescribers of Schedule II–V medications must complete:

  1. Identity proofing — One-time verification via a DEA-approved credential service.
  2. Two-factor authentication at signing — Separate from login MFA.
  3. DEA registration — Active DEA number on file.

Setup is initiated from My Profile > EPCS.

Email security@quiltedhealth.com. For urgent issues involving active unauthorized access, call the 24/7 incident line listed in your BAA.