Security built into the workflow

See what happens to a document from upload to audit history.

From identity and permission to secure storage and audit history, TeddyIQ keeps protection tied to the workflow.

The document journey

Every document passes through the right checks.

One path, in order. A document does not skip a stage, and it does not enter the workflow before the stage it is in has finished with it.

  1. Identity

    The person acting is authenticated first. Patients and staff sign in through separate identity systems, and a patient login can never open a workspace.

  2. Permission

    Role-based access decides what each person can reach. Approval and upload links work once, expire on a schedule and can be revoked.

  3. Secure upload

    Files move straight from the browser into encrypted storage, so the document does not sit anywhere along the way.

  4. Quarantine

    An uploaded file is held while the required safety checks run. Nothing enters the workflow before they pass.

  5. Document check

    The file is measured against the requirement it was requested for. A file that cannot be safely cleared stays blocked.

  6. Encrypted storage

    Documents are stored encrypted at rest under a dedicated encryption key that TeddyCare manages in its own cloud environment, rather than a shared provider default.

  7. Controlled access

    Who can open the document afterwards depends on authenticated identity, organization membership, assigned responsibility and role.

  8. Audit history

    Each event is added to the timeline so your team can see what happened and when.

The detail

Controls that ship today.

Encrypted in transit and at rest

TeddyIQ encrypts supported healthcare data while it is moving and while it is stored.

A clear record of what happened

TeddyIQ keeps an append-only audit history so earlier events cannot be edited or deleted through the application.

Every access is logged

Views, changes and downloads are written to that history alongside the work itself.

You control who sees what

Role-based access limits what each team member can reach, and patient permissions are tracked where the workflow requires them.

BAA available for covered entities

TeddyCare Medical signs Business Associate Agreements with covered entities and their business associates.

Uploads are checked before they count

Files are quarantined and scanned, and are released into the workflow only after the required checks pass.

Separate logins for patients and teams

Patients and staff sign in through separate identity systems that do not cross over.

Single-use, expiring links

Approval and upload links work once, expire on a schedule and can be revoked at any time.

Certification status

We do not claim certifications we have not earned.

Our current security controls and certification status are shared during security review. If a certification matters to your procurement process, ask us directly and we will tell you where we actually stand.

Ask us directly

Working with PHI

Protected healthcare workflows, with the agreements in place.

TeddyIQ is built to support HIPAA-regulated healthcare workflows through the safeguards on this page. TeddyCare Medical provides a Business Associate Agreement for covered healthcare customers where appropriate.

Security questions