HIPAA Compliance

MatchVox is built from the ground up for HIPAA compliance. We implement the Safe Harbor method to de-identify all protected health information (PHI) before it is used for trial matching or shared with clinical trial sites.

HIPAA Compliant

Safe Harbor Method

SOC 2 Type II

Annual Audit

AES-256

Encryption at Rest

TLS 1.3

Encryption in Transit

For Clinical Trial Sites

1

Patient Submits Health Profile

Patients enter their conditions, medications, and lab results. All data is stored encrypted on their device and our secure servers.

2

Automatic De-identification

Before matching, all 18 HIPAA identifiers are stripped. Names become random IDs. Dates become year-only. Zip codes are truncated to 3-digit prefixes.

3

Trial Matching Engine

Our algorithm matches de-identified profiles against trial eligibility criteria. Sites receive aggregate match scores, never individual patient details.

4

Patient-Initiated Contact

Only the patient can choose to contact a trial site. Sites never receive identifiable information unless the patient explicitly consents and initiates contact.

For Patients

Your name is never shared

Trial sites see de-identified profiles only

You control your data

Grant, modify, or revoke access anytime

Delete everything anytime

Full data deletion within 30 days of request

No data selling, ever

We never sell personal health information

Security Architecture

Safe Harbor De-identification

All patient data is processed through our Safe Harbor de-identification pipeline before being used for trial matching. This removes all 18 HIPAA identifiers per 45 CFR 164.514(b)(2).

AES-256 Encryption at Rest

All stored data is encrypted using AES-256 encryption. Database fields containing any health information use column-level encryption with regularly rotated keys.

TLS 1.3 in Transit

All data transmitted between your browser and our servers uses TLS 1.3 with perfect forward secrecy. No health data is ever sent over unencrypted connections.

Role-Based Access Control

Clinical trial sites see only de-identified, aggregate patient profiles. Individual patient data is never exposed to site coordinators or sponsors without explicit consent.

Audit Logging

Every access to patient health data is logged with timestamp, accessor ID, and action type. Audit logs are immutable and retained for 7 years per HIPAA requirements.

Patient Consent Management

Patients control exactly what data is shared and with whom. Consent can be granted, modified, or revoked at any time. All consent actions are audit-logged.

The 18 HIPAA Identifiers We Strip

Per the Safe Harbor method (45 CFR 164.514(b)(2)), the following 18 types of identifiers must be removed to de-identify protected health information.

1

Names

Full or partial names

2

Geographic Data

Address, city, county, zip (below state level)

3

Dates

Birth date, admission/discharge dates, death date

4

Phone Numbers

Home, mobile, work phone numbers

5

Fax Numbers

All fax numbers

6

Email Addresses

Personal and work email

7

Social Security Numbers

SSN / Tax ID

8

Medical Record Numbers

MRN, chart numbers

9

Health Plan Beneficiary Numbers

Insurance member IDs

10

Account Numbers

Financial or billing account numbers

11

Certificate/License Numbers

Medical licenses, DEA numbers

12

Vehicle Identifiers

VIN, license plate numbers

13

Device Identifiers

Medical device serial numbers, UDI

14

Web URLs

Personal websites, social profiles

15

IP Addresses

Network identifiers

16

Biometric Identifiers

Fingerprints, voiceprints, retinal scans

17

Full-face Photographs

Identifiable images

18

Any Other Unique Identifier

Any code that could identify an individual

Business Associate Agreements

MatchVox maintains Business Associate Agreements (BAAs) with all infrastructure providers, including cloud hosting, database, and storage services. Enterprise and clinical trial site partners can request a copy of our BAA for review. Contact our compliance team for details.