Data security and privacy
ExpiWell is HIPAA and GDPR compliant, and the controls behind that are monitored continuously rather than asserted once a year — the current status of every monitored control is published in a live trust report anyone can open.
The full, standing description of how research data is protected — encryption, hosting, the HIPAA safeguards and signed BAA, GDPR and data residency, access control, deletion and retention — lives at Data Security. For a formal statement of compliance, contact security@expiwell.com.
Accessibility
ExpiWell also maintains web accessibility to W3C WCAG 2.1 guidelines at the AA level — see the accessibility statement.
Working with your IRB
ExpiWell is trusted by IRBs in medical and clinical settings, and the team helps walk you through the IRB process — including providing the compliance verbiage your application needs. IRB Information collects what a review board asks, with a compliance statement you can cite directly. See also Enabling 2FA for your account.