Home Security & HIPAA
Trust & Compliance

How we protect patient health information

Canid works as a business associate to pediatric practices, so protecting patient data is a core part of the job. This page summarizes our HIPAA program in plain language for practices, IT teams, and compliance reviewers doing their diligence.

At a glance

Full HIPAA policy set: Privacy, Security, and Information Blocking, plus day-to-day workforce rules

Named Privacy Officer and Security Officer

Patient data encrypted in transit and at rest

Hosted on AWS with daily encrypted backups

HIPAA training for every team member, with documentation

Business associate agreement with every practice we serve

Breach notification on HIPAA timelines

Policies reviewed at least annually; last comprehensive review July 2026

The program

Canid maintains a complete HIPAA policy set covering the Privacy Rule, the Security Rule across administrative, physical, and technical safeguards, and the Information Blocking Rule from the 21st Century Cures Act, along with internal rules the whole team follows day to day. Pedro Sanchez de Lozada serves as Privacy Officer and Juliana Muñoz as Security Officer.

Every new team member completes HIPAA training, and compliance documentation is retained for six years as HIPAA requires. Policies are reviewed at least once a year, most recently in a comprehensive July 2026 review, and we work with an independent HIPAA compliance firm on security risk analysis.

How we protect data

Patient data lives in access-controlled production systems hosted on AWS. Electronic PHI is encrypted in transit and at rest, access follows the minimum-necessary standard through unique, role-based accounts, and system activity is audit-logged. Workstations follow a hardening standard that includes full-disk encryption, firewalls, automatic screen lock, and up-to-date malware protection.

Production databases are backed up automatically every day, with additional encrypted cold backups taken four times a week and retained for six years. Backup jobs are monitored and verified automatically, and failures alert the engineering team immediately.

Incidents and breach notification

We maintain a defined incident response process with a standing reporting channel the whole team is trained to use, and our policy is to report suspected incidents immediately rather than wait for certainty. If a breach of unsecured PHI occurs, we notify affected parties without unreasonable delay and within HIPAA's 60-day requirement, report to HHS, and follow the media notification rules for breaches affecting more than 500 people in a state.

BAAs, vendors, and patient requests

Canid signs a business associate agreement with every practice we serve, and vendors that handle PHI on our behalf are bound by business associate agreements of their own.

Requests for patient information are handled under the HIPAA Privacy Rule and the Information Blocking Rule: when a patient, provider, or authorized app has the right to health information, we make it available on the required timelines instead of getting in the way.

Who owns this

Two named officers own the program

Privacy Officer

Pedro Sanchez de Lozada

Founder & CEO. Owns the Privacy and Information Blocking policies, patient rights requests, and BAAs.

Security Officer

Juliana Muñoz

COO. Owns the Security policies, safeguards, incident response, and workforce security training.

Security inquiries

Working through a security review?

Send your questionnaire, BAA request, or any question about this page. Security inquiries go straight to our Privacy and Security Officers, and we'll get back to you within 1 business day.