Handling patient information carefully.
Equinox systems work with protected health information, and that shapes how they're built and how we contract. This page describes our approach. For the specifics your compliance team needs in writing, ask us — we'd rather send documentation than make claims on a marketing page.
Business Associate Agreement
We enter into a BAA with practices before handling protected health information, setting out how PHI may be used, safeguarded and disclosed.
Encryption in transit and at rest
Data moving between your systems and ours is encrypted in transit, and stored data is encrypted at rest.
Least-privilege access
Access to production systems and customer data is limited to the people whose role requires it, and is reviewed.
Audit trails
Actions taken in the platform are logged so your team can reconstruct what happened and when.
Escalation over assumption
When a system can't complete a task confidently — an ambiguous eligibility response, a caller with an unusual request — it flags a person rather than guessing.
Human review where it counts
Clinical documentation and coding suggestions require provider review and approval. Captured documents queue for staff review before chart upload.
Where Equinox actually runs.
Everything we operate is hosted on major cloud platforms that support HIPAA-eligible workloads under a Business Associate Agreement — not on hardware in a closet.
Hosted on AWS and Microsoft Azure
Equinox systems run on Amazon Web Services and Microsoft Azure. Both offer HIPAA-eligible services and will enter into a Business Associate Agreement covering the services we build on, which is a prerequisite for anything that touches PHI.
Microsoft stays inside your tenant
Where a system works with Microsoft services — the Teams alerts Nova sends when a patient checks in, for example — it operates within your organization's own private Microsoft environment, under your tenant and your administrators' control, rather than in one we run on your behalf.
Azure security enabled before go-live
During onboarding we work through the Azure security configuration with your IT team and confirm the relevant protections are switched on in your tenant before any system goes live.
Because Microsoft runs inside your own environment, your existing identity, access and retention policies apply to it — we don't ask you to route protected health information through a separate workspace we control. Your IT team keeps the administrative rights they already have.
What to ask us about
Yes. A Business Associate Agreement is executed before we handle protected health information on your behalf. Your counsel is welcome to review it and raise changes.
On AWS and Microsoft Azure, both of which support HIPAA-eligible workloads under a Business Associate Agreement. For your security review we'll put the specifics in writing — which regions, which services, which subprocessors, retention periods and internal access controls — rather than asking you to rely on a summary here.
They run inside your organization's own private Microsoft environment. The alerts Nova sends at check-in are delivered within your tenant, governed by your existing Microsoft agreements, identity controls and retention policies, with your administrators holding the rights they already hold. We don't move that traffic into a workspace we operate. As part of onboarding we go through the Azure security configuration with your IT team and confirm the relevant protections are enabled before go-live.
This is exactly the kind of question that deserves a contractual answer rather than a marketing one. Ask us during your review and we'll put our position and any model-provider terms in writing.
Ask for our current status. We'd rather tell you precisely where we are — including what is in progress and what isn't started — than imply a certification we don't hold.
Incident response and notification obligations are set out in the BAA and service agreement. We'll walk your team through the process before you sign.
A note on this page
Security claims should be verifiable. If anything here matters to your decision, ask for it in writing and hold us to the document rather than the website.
Send us your security questionnaire.
We'd rather work through your review early than discover a blocker after the demo.