Data security and privacy
ExpiWell is HIPAA and GDPR compliant, and the controls behind that are monitored continuously rather than asserted once a year. Compliance is checked in real time by Vanta, which reports on every aspect of compliance in real time, and the platform is used frequently for research that captures Protected Health Information (PHI). You can view the live trust report yourself.
HIPAA
Platform security and privacy comply with the Health Insurance Portability and Accountability Act. Concrete measures include:
- Data encrypted at rest and in transit
- Established backup, continuity, and disaster-recovery processes (tested)
- Vulnerability and system monitoring procedures
- Optional 2FA for researcher accounts — see Enabling 2FA for your account
- Anti-malware technology, employee background checks, and HIPAA training for all employees
- Physical safeguards at our hosting provider, guaranteed by a signed Business Associate Agreement (BAA)
GDPR
The platform has passed a third-party verification process for the requirements that apply to UK and EU customers, and ExpiWell has appointed EU and UK GDPR representatives. Separate US and EU deployments keep EU resident data in the EU region. See the GDPR policy and privacy statement.
For a formal statement of compliance, contact security@expiwell.com.
Accessibility
ExpiWell also maintains web accessibility to W3C WCAG 2.1 guidelines at the AA level, in partnership with accessiBe — see the accessibility statement.
Working with your IRB
ExpiWell is trusted by IRBs in medical and clinical settings, and the team helps walk you through the IRB process — including providing the compliance verbiage your application needs. See Institutional Review Board (IRB) information.