Data security and privacy
ExpiWell is third-party verified for both HIPAA and GDPR — not just self-claimed. Compliance is checked continuously with Vanta, which reports on every aspect of compliance in real time, and the platform is used frequently for research that captures Protected Health Information (PHI). You can view the live trust report yourself.
HIPAA
Platform security and privacy comply with the Health Insurance Portability and Accountability Act. Concrete measures include:
- Data encrypted at rest and in transit
- Established backup, continuity, and disaster-recovery processes (tested)
- Vulnerability and system monitoring procedures
- Optional 2FA for researcher accounts — see Enabling 2FA for your account
- Anti-malware technology, employee background checks, and HIPAA training for all employees
- Physical safeguards through Amazon Web Services, guaranteed by a signed Business Associate Agreement (BAA)
GDPR
The platform has passed a third-party verification process for the requirements that apply to UK and EU customers, and ExpiWell has appointed EU and UK GDPR representatives. Separate US and EU deployments keep EU resident data in the EU region. See the GDPR policy (in the EU, use app-v2-eu.expiwell.com/gdpr) and privacy statement (in the EU, use app-v2-eu.expiwell.com/privacy).
For a formal statement of compliance, contact security@expiwell.com.
Accessibility
ExpiWell also maintains third-party verified web accessibility, adhering to W3C WCAG 2.1 guidelines at the AA level in partnership with accessiBe — see the accessibility statement.
Working with your IRB
ExpiWell is trusted by IRBs in medical and clinical settings, and the team helps walk you through the IRB process — including providing the compliance verbiage your application needs. See Institutional Review Board (IRB) information.