| Control | Requirement | Status |
|---|---|---|
| Encryption at Rest | 45 CFR §164.312(a)(2)(iv) | ✅ AES-256 (InnoDB + file-level) |
| Encryption in Transit | 45 CFR §164.312(e)(2)(ii) | ✅ TLS 1.2/1.3 enforced, HSTS |
| Unique User IDs | 45 CFR §164.312(a)(2)(i) | ✅ Per-user accounts, no shared credentials |
| Automatic Session Timeout | 45 CFR §164.312(a)(2)(iii) | ✅ Configurable, minimum 15 minutes |
| Multi-Factor Authentication | 45 CFR §164.312(d) | ✅ TOTP + SMS OTP available |
| Audit Controls | 45 CFR §164.312(b) | ✅ Full audit log on all PHI access and writes |
| Role-Based Access Control | 45 CFR §164.308(a)(4) | ✅ 12-level role system, company-scoped |
| Encrypted Offsite Backup | 45 CFR §164.308(a)(7)(ii)(A) | ✅ GPG AES-256, Backblaze B2 |
| Emergency Access | 45 CFR §164.312(a)(2)(ii) | ✅ Emergency role 99 with audit trail |
| Integrity Controls | 45 CFR §164.312(c)(1) | ✅ Chart lock prevents modification post-signature |
EMStool LLC executes a Business Associate Agreement (BAA) with all covered entity customers prior to onboarding. To request a BAA or compliance documentation package, contact the Security Officer listed above.