Willowbridge and TenorMD operate under a single Willowcare information-security program. This page describes what's actually in place today — and what's on the roadmap.
An examination covering Security, Availability and Confidentiality is being scheduled across Willowcare and both products. We publish no badge until the report is issued.
Security Rule program with a designated Security & Privacy Officer; BAAs in place with every Willowbridge practice.
TLS 1.2+ in transit and AES-256 at rest, with managed key rotation.
U.S.-based hosting with strict per-tenant isolation and mandatory MFA on all administrative access.
Operates as a HIPAA Business Associate and signs a BAA with every practice. PHI is encrypted, tenant-isolated, and access is logged and least-privilege. Care-time records are tamper-evident to support billing review and audit.
Built to hold no PHI. Feedback is anonymous by design and aggregated to protect respondents. A BAA is available on request for organizations that prefer one.
A representative register of the infrastructure providers behind the products. The full, current list is available on request.