Skip to main content
Rushin InTegrations

Trust & Security

Your data. Our responsibility.

Kevin! is built from the ground up for healthcare. We implement the security and compliance safeguards your patients and practice deserve, because trust isn't optional when lives are involved.

On this page

Security at a glance

  • Encrypted everywhere

    TLS 1.2+ in transit, AES-256 at rest. Your data is encrypted at every stage.

  • HIPAA compliant

    Full administrative, physical, and technical safeguards per HIPAA Security Rule.

  • SOC 2 infrastructure

    Hosted on Google Cloud Platform, with SOC 2 Type II–audited data centers.

  • Continuous monitoring

    Real-time intrusion detection, vulnerability scanning, and audit logging.

Infrastructure & encryption

Technical safeguards

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for all data at rest
  • Role-based access controls (RBAC)
  • Multi-factor authentication (MFA)
  • Regular vulnerability scanning & pen testing
  • Automated security patching
  • Secure software development lifecycle

Administrative safeguards

  • Designated Privacy & Security Officers
  • Workforce HIPAA training
  • Documented security policies & procedures
  • Regular risk assessments & audits
  • Background checks for data-access roles
  • Vendor security assessments
  • Incident response plan & procedures

Google Cloud Platform. All data is hosted on GCP infrastructure with SOC 2 Type II attestation, ISO 27001 compliance, and a signed HIPAA Business Associate Agreement. View Google Cloud compliance

HIPAA compliance

When healthcare providers use Kevin! to process Protected Health Information (PHI), Rushin InTegrations acts as a Business Associate under HIPAA. We implement the full spectrum of safeguards required by the HIPAA Security Rule and maintain strict compliance with the Privacy Rule and Breach Notification Rule.

BAAs available
We provide Business Associate Agreements for all healthcare customers before any PHI is transmitted.
Access controls
Role-based access, MFA, and minimum necessary standard. We access only the PHI needed to deliver services.
Workforce training
All team members receive mandatory HIPAA privacy and security training with annual refreshers.
Breach notification
Formal incident response plan with notification to covered entities within 60 days of discovery.
  • HIPAA Security Rule
  • HIPAA Privacy Rule
  • HITECH Act
  • Breach Notification Rule

AI & your data

ProviderUsed forBAATraining / saleRetention
GoogleGemini inferenceSignedNo training or sale under our BAANo retention for provider purposes
OpenAIGPT inferenceSignedNo training or sale under our BAANo retention for provider purposes
Rushin InTegrationsService delivery, audit, support, and HIPAA operationsCustomer BAA availableNo sale or general-purpose model trainingOnly as needed for Services and HIPAA/BAA duties; AES-256 at rest
AI processing
AI inference uses current Google Gemini and OpenAI GPT models under signed BAAs with Google and OpenAI. Those agreements require confidential handling and prohibit using PHI or clinical inputs to train models or sell data.
Voice dictation
Audio is processed in real-time and deleted immediately after transcription. Raw audio is never retained unless you explicitly opt in. Speech-to-text is powered by AssemblyAI under a signed BAA.
Subprocessor obligations
All subprocessors are contractually bound to process data only as instructed, never use your data for their own purposes, maintain equivalent security standards, keep information confidential, and enter into BAAs where required.

Incident response

We maintain a formal Incident Response Plan that defines how we detect, contain, investigate, and resolve security incidents. In the event of a breach of unsecured PHI:

  1. Rapid detection

    Continuous monitoring and automated alerting to identify incidents in real-time.

  2. Immediate containment

    Affected systems are isolated within hours. Evidence is preserved for investigation.

  3. Timely notification

    Covered entities notified within 60 days of discovery, with full incident details.

Every incident is documented, reviewed, and used to strengthen our security posture. Post-incident reviews are conducted within 14 days of closure.

Documentation & resources

Security questions?

We're happy to discuss our security practices, provide compliance documentation, or walk through our architecture with your IT team.