ProductCustomersPlatformJournalGlossaryMigrateFor CliniciansSecurity>_  Agent viewGet Started
Security & compliance

Built for diligence.

If you run patients through Lithos, your counsel and your compliance team will have questions. This page is for them — and anything it does not answer, we will put in writing.

BAASIGNED AT ONBOARDING

HIPAA, with a BAA at onboarding

Lithos operates as a HIPAA business associate. A Business Associate Agreement is part of standard onboarding — not an enterprise add-on.

SOC 2Type IIControls designedEvidence collectionAuditor report

SOC 2 Type II underway

Our SOC 2 Type II audit is in progress; the report is shared with customers and prospects under NDA as soon as it is available.

09:41:07encounter.createdenc_51b009:44:32encounter.in_reviewdr_2e1109:45:10encounter.approveddr_2e1109:45:11order.createdord_77c2

Every clinical action logged

Visits, prescriptions, benefit checks, lab orders — every clinical action is captured in an audit log you can export via API.

export · any timeYoursanytime · even leaving

Your data is yours

You own all patient and operational data. Export it anytime through the API — including if you decide to leave.

2FA · 428 916IDENTITY-PROOFEDPRESCRIBER

EPCS e-prescribing

Controlled-substance prescribing runs through EPCS with identity-proofed prescribers, as DEA rules require.

Patient recordrole-based · loggedONLY THE CARE TEAM

Access on a need-to-know basis

Clinical data access is role-based and logged. Patients are visible only to the clinicians and staff involved in their care.

Get started

From first call to first patient, in weeks.

A 15-minute intro call, sandbox credentials the same day, go-live in 3–4 weeks — new launches and existing patient bases alike.