← Back

Security & HIPAA Compliance

Last updated: April 6, 2026

RFoodX is a HIPAA-compliant platform built for medically-tailored meal delivery operations. We handle Protected Health Information (PHI) for Medi-Cal members and take our obligation to protect that data seriously. This page describes the technical, administrative, and physical safeguards we maintain.

HIPAA Compliance

RFoodX is designed to meet the requirements of the HIPAA Security Rule (45 CFR Part 164, Subpart C) and the HIPAA Privacy Rule (45 CFR Part 164, Subpart E). Our compliance program includes:

Authentication & Access Control

We enforce strict access controls to ensure only authorized personnel can access PHI:

Data Encryption

Database Security

Audit Trail

All access to PHI is logged in an immutable audit trail. Audit records include:

Audit logs are retained for a minimum of 6 years as required by HIPAA.

Infrastructure

Application Security

Incident Response

In the event of a security incident or potential breach, RFoodX follows a documented incident response plan that includes:

Regular Assessments

We conduct regular security assessments including:

Responsible Disclosure

If you discover a security vulnerability in our platform, please report it responsibly by contacting us at security@rfoodx.com. We take all reports seriously and will respond within 48 hours.

Contact

For security inquiries or to request documentation of our HIPAA compliance program, contact: