Security & Compliance
Behavioral health doesn't get a privacy do-over.
Skillique protects PHI and SUD records the way the regulations actually require — not the way it's convenient to.
HIPAA-aware
Encryption at rest and in transit, BAAs with every subprocessor, and access controls modeled on the Privacy & Security rules.
42 CFR Part 2
SUD records receive heightened consent management, segmented access, and explicit re-disclosure tracking.
Role-based access
Granular RBAC with attribute conditions: clinicians see only their caseload by default; supervisors see their team; owners see everything.
Audit trails
Every read, write, sign, and disclose is logged with actor, timestamp, IP, and reason. Exportable for any audit.
SSO & MFA
SAML and OIDC SSO via Okta or Microsoft Entra. MFA enforced for all production access. SCIM provisioning supported.
US data residency
PHI stored exclusively in US-East and US-West regions. No cross-border transfer. Backups are encrypted and region-pinned.
Compliance posture
Need our security packet?
We share BAAs, SOC 2 reports, pen test summaries, and architecture diagrams under NDA. Most security reviews close in under 10 days.