Security & Compliance — FITWithRCMC

Security & Compliance

Last updated: September 3, 2026

Responsibilities are defined in writing, not on this page. Every clinic signs a Business Associate Agreement with us before onboarding. That agreement — not this page — governs how PHI is handled and where responsibility sits between your clinic and FITWithRCMC.

Data Storage

  • Hosted on Supabase (Postgres)
  • Encrypted in transit and at rest
  • Row-level security, isolated per clinic
  • Data is stored in the United States

Infrastructure

  • Underlying provider is SOC 2 Type II audited
  • Access logging on all patient records
  • Role-based staff permissions

Incident Response

If we become aware of a security incident affecting your Clinic's data, we will notify you without unreasonable delay, consistent with the notification timelines and process set out in your signed BAA. Specific breach notification obligations and timelines are governed by that agreement, not by this page.

Your Agreement

  • Signed BAA required before go-live
  • Defines each party's HIPAA responsibilities
  • Contact us to request a copy: [email protected]

Questions

For security or compliance questions, contact [email protected].