Texoft

Security Statement

What we do to protect your systems and your patients' data — written for the compliance officer, attorney or insurer who has to verify it.

Last updated 29 August 2026

Practices hand us their network, their systems and, under agreement, their patient data. This page states plainly how we protect it. If your compliance officer, attorney or cyber insurer needs this in a questionnaire, send them here first — and then ask us for anything it does not cover.

Our security posture

Texoft is a healthcare technology provider, which means we operate under two obligations at once: securing our own business, and acting as a HIPAA business associate for the practices we serve. We design for the second, stricter standard throughout.

We state what we do, not what sounds good. Texoft does not currently hold SOC 2, HITRUST or ISO 27001 certification, and we will not claim otherwise on a questionnaire. What follows are the safeguards actually in place. If a certification is a contractual requirement for you, tell us early so we can discuss a realistic path.

Administrative safeguards

  • Written policies and procedures covering privacy, security, access management, sanctions, and incident handling — reviewed at least annually.
  • Annual HIPAA privacy and security training for every person with access to client systems, with completion records retained.
  • Security Risk Assessment performed on our own environment on the same cadence we require of clients.
  • Least-privilege access — access to a client environment is granted for a named purpose, scoped to what the work requires, and reviewed when an engagement changes or ends.
  • Documented joiner, mover and leaver process so access is provisioned and revoked deliberately rather than accumulating.
  • Vendor governance — any subprocessor that could touch client data is assessed and placed under agreement before use.

Technical safeguards

  • Multi-factor authentication on all administrative accounts, ours and, wherever we control the configuration, our clients'.
  • Encryption in transit for all data we move, and encryption at rest on endpoints and storage under our management.
  • Unique named accounts — no shared administrative credentials, no generic logins.
  • Credential management through a dedicated password manager, never in documents, spreadsheets or email.
  • Endpoint protection and patch management on managed devices, with monitoring for missed updates.
  • Logging and audit trails for administrative actions taken in client environments, retained so activity can be reconstructed.
  • Segmented networks separating clinical systems, guest access and building-automation devices such as cameras, locks and sensors.
  • Approval gates on destructive actions — our automation tooling presents a plan and requires human confirmation before anything irreversible runs, and retains a snapshot so the change can be reversed.

Physical safeguards

The HIPAA Security Rule requires physical safeguards, not only digital ones. We apply them to our own operations and design them for clients:

  • Facility access control — restricted areas holding records, servers or medication are on access-controlled locks with per-person audit trails, not shared keys.
  • Workstation security — screen positioning, automatic locking and clear-desk practice in patient-facing areas.
  • Device and media controls — inventory of equipment holding data, and documented sanitization or destruction before any device is reused, returned or disposed of.
  • Camera and sensor governance — retention periods set deliberately, footage access restricted and logged, and cameras never placed where they would capture clinical encounters or screens displaying PHI.

HIPAA and Business Associate Agreements

Texoft signs a Business Associate Agreement before accessing any system that contains Protected Health Information. This is not optional and not something we do after the fact.

  • We execute a BAA with every covered entity we serve, and we flow equivalent obligations down to any subcontractor that could encounter PHI.
  • We use PHI only as permitted by the agreement and only as needed to deliver the contracted service.
  • We do not use client PHI to train models, build products, or for any purpose beyond the engagement.
  • We will provide our standard BAA on request, and we will review yours.

42 CFR Part 2

Behavioral health and substance use disorder practices carry an obligation stricter than HIPAA alone. Where Part 2 applies, records generally require patient consent even for treatment, payment and healthcare operations, and standard vendor agreements are not sufficient.

  • We identify Part 2 applicability during assessment rather than assuming HIPAA-only.
  • Vendors and tools introduced into a Part 2 environment must be covered by a Part 2-aware agreement.
  • We do not deploy advertising pixels, retargeting or general-purpose analytics on pages describing addiction or SUD treatment.
  • AI-generated clinical or patient-facing content requires clinician review before publication.

Subprocessors and tooling

We keep the list of systems that could touch client data deliberately short, and we will disclose the current list on request as part of due diligence. Our standing rules:

  • No consumer AI tools are used with PHI. Where AI is deployed in a clinical workflow, it runs on a healthcare-specific platform under a BAA.
  • Any tool entering a client environment is assessed for its data handling, contractual terms and security posture before deployment — not after.
  • We tell clients in advance when a new subprocessor would be introduced into their environment.

Incident response

We maintain a written incident response procedure covering detection, containment, assessment, notification and post-incident review.

StageWhat happens
Detect & containIsolate affected systems and stop ongoing exposure before anything else.
Notify the clientWe contact the affected practice promptly on discovery of a suspected incident involving their environment — before we have all the answers, not after.
AssessDetermine what was accessed, by whom, and whether it constitutes a reportable breach under HIPAA or state law.
Support notificationBreach notification to patients, HHS and state authorities is the covered entity's legal duty. We provide the technical findings, timeline and documentation they need to meet it.
ReviewWritten post-incident review with the corrective actions taken, so the same gap does not reopen.

Backup and continuity

  • Backups for managed environments are configured with defined retention and, where the environment allows, an offsite or immutable copy.
  • Restores are tested, not assumed. An untested backup is a hope, not a control.
  • Recovery objectives are agreed with each client rather than inherited from a default, and documented in the service agreement.

What we ask of clients

Security is shared. These are the things we cannot do for you:

  • Do not send PHI through our website form, ordinary email or text message. Ask us for a secure channel and we will set one up.
  • Tell us promptly when staff join or leave so access can be provisioned and revoked on time.
  • Keep a designated Privacy Official and Security Official named and current.
  • Let us know before introducing a new system that will touch patient data, so it can be assessed and put under agreement first.

Reporting a security concern

If you believe you have found a vulnerability in our systems, or you suspect an incident affecting your environment, contact us directly and mark it urgent. We will acknowledge and begin assessment promptly, and we will not pursue action against anyone who reports a genuine issue in good faith.

Phone: (727) 330-2111
Email: info@texoft.us
Texoft — Transworld Medical Management, LLC, Tampa Bay, FL

This statement describes our practices and is provided for information. It does not modify any executed Business Associate Agreement or Service Agreement, which control in the event of a conflict.