Administrative safeguards
Access is provisioned around job responsibility and the minimum information necessary. Operational practices address account management, workforce access, change control, incident handling, and ongoing review.
Security and HIPAA
WellReady is built and operated for HIPAA-compliant handling of protected health information and personally identifiable information across behavioral health, recovery housing, treatment court, and community programs.
Security by responsibility
HIPAA requires administrative, physical, and technical safeguards to work together. WellReady pairs the protected foundation of Microsoft Azure with application controls, operating practices, and role-aware workflows designed around sensitive behavioral health information.
This public overview explains the control model without publishing sensitive configuration details. Deeper architecture, implementation evidence, and organization-specific responsibilities can be addressed during a formal security review.
HIPAA safeguard framework
Access is provisioned around job responsibility and the minimum information necessary. Operational practices address account management, workforce access, change control, incident handling, and ongoing review.
Unique user access, role-based permissions, tenant boundaries, encrypted data handling, session controls, and traceable activity help protect the confidentiality and integrity of electronic PHI.
Production data and services are hosted on Microsoft Azure. Azure provides the protected physical and cloud foundation, while WellReady manages application, tenant, identity, and operational controls above it.
Control areas
Controls are layered so no single setting carries the full responsibility for protecting sensitive records.
Unique accounts and role-specific permissions support least-privilege access across administrative, clinical, operational, peer, billing, and court functions.
Each organization’s production environment is separated around its users, programs, configuration, and records to reduce unintended cross-tenant exposure.
PHI and PII are protected through encrypted transport and encrypted storage within the production environment.
Security-relevant and record-level activity is designed to remain attributable so organizations can review who did what and when.
Managed continuity, backup, and recovery practices are incorporated into production operations to support restoration after an interruption.
Production changes are controlled, reviewed, and validated. Security findings are assessed, prioritized, remediated, and retested according to risk.
Data lifecycle
Security decisions follow the information throughout its lifecycle, not only while it is sitting in a database.
Capture only the information needed for authorized care, housing, program, billing, and reporting workflows.
Keep production PHI and PII within the protected Azure-hosted environment and its controlled services.
Apply role and tenant boundaries so information is available to the right people for the right purpose.
Use deliberate releases, permissions, and workflow-specific views instead of broad record exposure.
Align retention, export, and deletion decisions with organizational requirements, applicable agreements, and legal obligations.
Testing and assurance
WellReady supports coordinated non-destructive and destructive security validation in an authorized, isolated environment using fictional data. Destructive testing should not be performed against a live production tenant or any environment containing real PHI.
Identify the environment, accounts, systems, test cases, time window, and stop conditions before testing begins.
Use synthetic records, dedicated test identities, and an isolated tenant with no connection to real client information.
Record expected results, timestamps, logs, observed behavior, impact, and restoration outcomes for each test.
Confirm restoration, remediate findings by risk, and repeat the relevant test to verify the control now behaves as intended.