Security
Designed for trust from day one
Security is not a feature layered on later at Leitara. It is a foundational design constraint.
Leitara is built to support sensitive clinical work, and we design our systems to minimize risk, limit exposure, and protect trust—without adding unnecessary complexity for clinicians or clients.
Our security principles
We design Leitara around a small set of guiding principles:
- Least privilege – access is limited to what is strictly necessary
- Compartmentalization – systems and data are segmented to reduce blast radius
- Encryption by default – data is protected in transit and at rest
- Minimal data footprint – we collect and retain only what is required
- Operational restraint – fewer moving parts means fewer failure modes
Security, like efficiency, works best when it is quiet.
Data protection
Encryption
- Data is encrypted in transit using industry-standard TLS
- Data is encrypted at rest using modern encryption standards
- Encryption keys are managed securely and access-controlled
Access controls
- Role-based access controls (RBAC)
- Principle of least privilege enforced across systems
- Administrative access is tightly restricted and audited
Data isolation
- Logical separation between organizations and users
- Compartmentalized services to limit cross-system exposure
- Clear boundaries between application layers
HIPAA
Leitara is designed to support HIPAA-compliant workflows.
Where applicable:
- We operate as a service provider to covered entities
- Protected health information (PHI) is handled in accordance with HIPAA requirements
- Administrative, technical, and physical safeguards are implemented to protect PHI
- A Business Associate Agreement (BAA) is available upon request
Clinicians and practices remain responsible for their professional and regulatory obligations.
Infrastructure and operations
Leitara is hosted on modern, reputable cloud infrastructure with strong physical and operational security controls.
Operational practices include:
- Secure configuration management
- Regular system updates and patching
- Monitoring for availability, performance, and security events
- Controlled deployment and change management processes
We prioritize stability and predictability over rapid, risky change.
Monitoring and auditing
We maintain logging and monitoring appropriate to the sensitivity of the system, including:
- Authentication and access events
- System health and error conditions
- Security-relevant operational signals
Monitoring is used to protect the Service—not to profile users or clients.
Incident response
Despite best efforts, no system can eliminate all risk.
Leitara maintains procedures to:
- Detect and respond to security incidents
- Contain and mitigate impact
- Notify affected parties as required by law or agreement
- Review and improve safeguards following incidents
Data minimization and retention
We intentionally limit:
- what data is collected
- how long it is retained
- who can access it
Clinical data remains under the control of the clinician or practice and can be managed in accordance with applicable agreements and legal requirements.
Third-party services
Where third-party services are used to support infrastructure or operations:
- Providers are selected for security and reliability
- Access is restricted to what is necessary
- Data handling is governed by contractual obligations consistent with this security posture
We do not use third-party services for advertising or behavioral tracking.
What we don't do
To be explicit, Leitara does not:
- sell or monetize data
- run advertising or tracking networks
- scrape or analyze content for marketing purposes
- share data outside the scope of providing the Service
Responsible disclosure
We appreciate responsible disclosure of potential security issues.
If you believe you have identified a vulnerability, please contact us at:
We will review reports promptly and handle them responsibly.
Questions?
We understand that security requirements vary by practice and context.
If you have questions about Leitara's security posture, BAAs, or compliance alignment, we're happy to discuss them.
Contact: security@leitara.com
Security is not about adding friction.
It's about removing uncertainty.
