Security & Compliance

Built to protectpatients, crews, and agency data

Air medical operations run on the most sensitive data there is. AAMELF protects it with encryption, database-enforced access control, PHI access logging, and complete audit trails, so your agency stays in command and in compliance.

Patient Data Protection (PHI)

Protected Health Information is treated as the most sensitive data on the platform and protected at every layer.

Encryption at rest
Patient identifiers, injury details, age, and clinical notes are stored encrypted on the mission record, not in plain text.
Decryption only when authorized
Clear-text PHI is exposed exclusively through a row-level-security-scoped view, so only users entitled to a mission can ever see its patient data.
PHI access logging
Every read of protected health information is recorded, giving administrators an auditable trail of who viewed what and when.

Access Control

Access is scoped to the agency and the role, enforced in the database rather than trusted from the client.

Row-level security (RLS)
Postgres row-level security ensures members only ever query rows belonging to their own agency, enforced at the data layer.
Role-based access
Responders, dispatchers, hospitals, and administrators each receive a purpose-built experience with only the permissions their role requires.
Authenticated sessions
Managed authentication with secure session handling gates every dashboard and privileged action.

Secure Infrastructure

Privileged operations run on the server against validated inputs, never on unchecked client trust.

Server-side privilege
Sensitive reads and writes run through server routes using a service role, keeping elevated credentials off the client entirely.
Agency-scoped ingestion
Telemetry and mission data are validated against the owning agency before they are accepted, preventing cross-agency spoofing.
Managed, encrypted transport
Data is served over encrypted connections on managed cloud infrastructure with continuous patching.

Auditability & Accountability

Air medical operations demand a defensible record. AAMELF keeps one automatically.

Comprehensive audit logs
Mission changes, aircraft assignments, and administrative actions are logged for review and reporting.
Chain-of-custody records
Organ and medical-cargo movements retain custody handoffs end-to-end for a complete provenance trail.
Operational safeguards
Dispatch surfaces warnings for degraded command-and-control links and infeasible flights so unsafe assignments are caught early.

Designed with healthcare privacy in mind

AAMELF is engineered around HIPAA privacy principles for handling Protected Health Information, including data minimization, least-privilege access, and auditable disclosure. For a Business Associate Agreement, a security questionnaire, or details on your agency's specific compliance requirements, our team is ready to help.

Have security questions?

Talk to our team about encryption, access control, audit logging, and compliance for your agency.