HIPAA is a legal and operational framework. Provider workflows subject to HIPAA require the appropriate Business Associate Agreements, account configuration, and operating procedures.
Controls currently implemented
- HTTPS at the public domain, secure HTTP-only session cookies, password hashing, login throttling, same-origin write checks, and browser security headers.
- Encrypted AWS storage with managed key rotation and automatic filesystem backups.
- User-scoped database access, pilot-controlled shares, expiring packet links, revocation, and access events.
- Direct identity values separated from medical-workflow rows through UUID references in a dedicated PII vault.
- Identity documents kept outside the ordinary document vault and excluded from AME and records-desk views.
- Packet-specific provider grants, verified practice membership, versioned reviews, and grant-scoped audit events.
Operating requirements for regulated health data
Organizations using Preflight Records in a regulated workflow must maintain the controls and agreements that apply to their role:
- Applicable HIPAA, FTC Health Breach Notification Rule, state privacy, release, and signature requirements.
- Required Business Associate Agreements with infrastructure and service providers that handle regulated health information.
- Documented security risk analysis, incident response, breach notification, workforce access, and recurring control review.
- Credential verification and role-based access for AMEs and practice team members.
- Audit retention, availability monitoring, restore testing, and vulnerability management.
- Validated records-release forms and state-specific release requirements.
Data handling boundaries
Preflight Records organizes and routes records. It does not diagnose, provide medical advice, determine airworthiness, or replace FAA MedXPress, the Aerospace Medical Certification Subsystem, an Aviation Medical Examiner, or a military aeromedical authority.
Report a security concern
Use the contact form and choose “Security report.” Do not include patient data, pilot records, credentials, or exploit payloads containing real information.