Security and trust

Built for protected health information.

A pre-visit history is clinical data, so it is treated as protected health information from the first tap. Here is how LinkBox handles it.

The posture

What a practice checks before it signs.

HIPAA and HITECH

Built for protected health information from the ground up, not retrofitted onto a general-purpose tool.

A BAA is included

A Business Associate Agreement (BAA) is part of the engagement and establishes the contractual terms under which a vendor may handle PHI on behalf of a practice, as required by HIPAA.

SOC 2-aligned integration

Upon integration, your system would incorporate controls designed to support SOC 2 compliance, including multi-factor authentication, user access logging, and penetration testing. These controls, together with the other applicable policies, procedures, and safeguards across the integrated system, contribute to meeting the relevant SOC 2 criteria.

Authenticated access

Physicians reach histories through the credentials they already use, with Doximity single sign-on rather than a new password to manage.

A note on the difference, because the two get confused. A BAA is a contractual agreement that defines the parties' HIPAA-related obligations for handling protected health information. SOC 2 is a market badge that speaks to a company's security processes. They sit side by side: the badge is about practice, the agreement is about the contractual handling of PHI. LinkBox will not make a compliance promise it cannot keep, and reviews specific requirements with each practice directly.

The buyer's checklist

Answered before you ask.

Is LinkBox HIPAA compliant?

LinkBox is built for protected health information and operates under HIPAA and HITECH. Because a pre-visit history is clinical data, it is handled as PHI from the moment a patient enters it. Compliance is treated as the baseline the product is designed around, not a feature bolted on later.

Does LinkBox provide a business associate agreement?

Yes. A business associate agreement, or BAA, is the contract that governs how a vendor may handle protected health information on a practice's behalf, and LinkBox includes one. It is the contractual agreement that defines both parties' HIPAA obligations so a practice can use the platform with PHI while keeping it clear where responsibility sits.

Is LinkBox SOC 2 certified?

LinkBox speaks for its own system and for the integration itself, not for a practice's whole environment. Upon integration, your system would incorporate controls designed to support SOC 2 compliance, including multi-factor authentication, user access logging, and penetration testing. These controls, together with the other applicable policies, procedures, and safeguards across the integrated system, contribute to meeting the relevant SOC 2 criteria. It sits alongside the BAA rather than replacing it: the badge speaks to process, the agreement speaks to the contractual handling of PHI.

Where do patient histories live?

A patient's history is tied to their chart and reaches the practice through the physician's authenticated account, using the same Doximity single sign-on credentials a physician already has. LinkBox shares specific data-handling and hosting details with a practice during onboarding, where they can be reviewed against that practice's own requirements.

Bring your security checklist to the demo.