HIPAA Compliance
MatchVox is built from the ground up for HIPAA compliance. We implement the Safe Harbor method to de-identify all protected health information (PHI) before it is used for trial matching or shared with clinical trial sites.
HIPAA Compliant
Safe Harbor Method
SOC 2 Type II
Annual Audit
AES-256
Encryption at Rest
TLS 1.3
Encryption in Transit
For Clinical Trial Sites
Patient Submits Health Profile
Patients enter their conditions, medications, and lab results. All data is stored encrypted on their device and our secure servers.
Automatic De-identification
Before matching, all 18 HIPAA identifiers are stripped. Names become random IDs. Dates become year-only. Zip codes are truncated to 3-digit prefixes.
Trial Matching Engine
Our algorithm matches de-identified profiles against trial eligibility criteria. Sites receive aggregate match scores, never individual patient details.
Patient-Initiated Contact
Only the patient can choose to contact a trial site. Sites never receive identifiable information unless the patient explicitly consents and initiates contact.
For Patients
Your name is never shared
Trial sites see de-identified profiles only
You control your data
Grant, modify, or revoke access anytime
Delete everything anytime
Full data deletion within 30 days of request
No data selling, ever
We never sell personal health information
Security Architecture
Safe Harbor De-identification
All patient data is processed through our Safe Harbor de-identification pipeline before being used for trial matching. This removes all 18 HIPAA identifiers per 45 CFR 164.514(b)(2).
AES-256 Encryption at Rest
All stored data is encrypted using AES-256 encryption. Database fields containing any health information use column-level encryption with regularly rotated keys.
TLS 1.3 in Transit
All data transmitted between your browser and our servers uses TLS 1.3 with perfect forward secrecy. No health data is ever sent over unencrypted connections.
Role-Based Access Control
Clinical trial sites see only de-identified, aggregate patient profiles. Individual patient data is never exposed to site coordinators or sponsors without explicit consent.
Audit Logging
Every access to patient health data is logged with timestamp, accessor ID, and action type. Audit logs are immutable and retained for 7 years per HIPAA requirements.
Patient Consent Management
Patients control exactly what data is shared and with whom. Consent can be granted, modified, or revoked at any time. All consent actions are audit-logged.
The 18 HIPAA Identifiers We Strip
Per the Safe Harbor method (45 CFR 164.514(b)(2)), the following 18 types of identifiers must be removed to de-identify protected health information.
Names
Full or partial names
Geographic Data
Address, city, county, zip (below state level)
Dates
Birth date, admission/discharge dates, death date
Phone Numbers
Home, mobile, work phone numbers
Fax Numbers
All fax numbers
Email Addresses
Personal and work email
Social Security Numbers
SSN / Tax ID
Medical Record Numbers
MRN, chart numbers
Health Plan Beneficiary Numbers
Insurance member IDs
Account Numbers
Financial or billing account numbers
Certificate/License Numbers
Medical licenses, DEA numbers
Vehicle Identifiers
VIN, license plate numbers
Device Identifiers
Medical device serial numbers, UDI
Web URLs
Personal websites, social profiles
IP Addresses
Network identifiers
Biometric Identifiers
Fingerprints, voiceprints, retinal scans
Full-face Photographs
Identifiable images
Any Other Unique Identifier
Any code that could identify an individual
Business Associate Agreements
MatchVox maintains Business Associate Agreements (BAAs) with all infrastructure providers, including cloud hosting, database, and storage services. Enterprise and clinical trial site partners can request a copy of our BAA for review. Contact our compliance team for details.
