Security at ResQ Medical

How ResQ Protects Your Institution’s Duty-Hour Data

ResQ Medical records resident and fellow duty hours for graduate medical education programs. Programs trust us with their trainees’ names, institutional email addresses, program and training-level assignments, and the times they enter and leave the WorkZones™ their institution defines. This page explains how that data is protected. It is written to answer the questions security reviews ask; if yours is not here, contact us at the address at the bottom of this page.

Last reviewed 2 October 2026

The short answers

Patient data

None. No clinical or billing data, and no connection to any EHR.

Location data

Entry and exit events only. Precise coordinates are never stored on ResQ servers.

Hosting

Microsoft Azure, United States (West US).

Tenancy

A dedicated application instance and database per institution.

Encryption

TLS 1.2 or 1.3 in transit. Databases, storage and backups encrypted at rest.

Sub-processors

Six named below, all US-hosted.

What we hold, and what we do not

WorkTime™ records who a trainee is, which program they belong to, and when they entered and left a WorkZone™. It does not hold patient information, clinical data or billing data, and it is not connected to any electronic health record. Precise location coordinates are never stored on ResQ servers; the mobile app’s location is evaluated against the institution’s geofences and only the entry and exit events are kept. Duty-hour records are not protected health information under HIPAA, and no payment card data is processed.

Where your data lives

Every institution runs on its own dedicated application instance and its own dedicated database, reached at its own hostname. There is no shared application and no shared database across customers. All production systems run in Microsoft Azure in the United States (West US), and institutional data does not leave the United States. Microsoft Azure’s physical and environmental controls are covered by its SOC 2 Type 2 report, available through the Microsoft Service Trust Portal.

ResQ requires no connection into your network and no accounts on your systems. The mobile app and the web portal talk only to ResQ-hosted services over HTTPS.

Encryption

All traffic between the mobile app, the web portal and ResQ services uses TLS 1.2 or 1.3 with forward-secret cipher suites; older protocols are refused. Databases are encrypted at rest with Azure SQL Transparent Data Encryption and storage is encrypted at rest with Azure Storage encryption. Backups are encrypted. Passwords are stored as salted, iterated hashes. A small set of older credentials created under a previous scheme is migrated to the same protection the next time that person signs in. One-time sign-in codes are stored only as keyed hashes.

Signing in

Residents sign in with a one-time code sent to their institutional email address, so access inherits your institution’s own email security and multi-factor authentication. Administrator sign-in is moving to the same one-time codes. Codes expire in twenty minutes, allow a limited number of attempts, and requests are rate-limited per address and per source. Administrator sessions in the web portal end after thirty minutes of inactivity. Access within the portal is role-based: program administrators see only the programs assigned to them, GME administrators see their institution, and trainees see only their own records in the app.

Who at ResQ can see your data

A small engineering and support team operates the service. Staff access to institutional data is limited to what operating the service and resolving support requests requires, is governed by our Access Control Policy, and administrative changes are recorded. Production database access is restricted to named administrator workstations and reviewed annually.

Backups and recovery

Every production database has 35-day point-in-time restore and long-term retention of weekly, monthly and yearly backups for seven years. Backups are managed by Azure, encrypted, and stored separately from the application, so they cannot be altered from the service. A documented business continuity and disaster recovery plan is in place.

Monitoring and vulnerability management

The Azure environment, our identity provider, our source-control platform and staff devices are monitored continuously through a compliance platform, and production configuration is checked against policy. Public-facing systems are scanned for vulnerabilities on a recurring basis; an independent automated security assessment of the web application in June 2026 reported no critical, high or medium findings. Vulnerabilities are remediated under documented timeframes by severity. Dependencies are pinned and reviewed with every change, and every change to the service goes through code review, automated tests and a staged deployment before it reaches institution instances.

Incident response

ResQ maintains a formal incident response plan with defined severity levels, escalation and root-cause analysis. If an incident affects your institution’s data, we notify the institution’s administrators in line with our contractual and legal obligations. ResQ carries cyber liability insurance.

Our compliance program

ResQ operates a SOC 2 (Security) program on a continuous-monitoring platform, with fifteen approved information-security policies covering access control, cryptography, data management, secure development, operations, third-party management, incident response and business continuity. A SOC 2 report has not yet been issued; program status and policy documents are available to customers under NDA on request. Our privacy policy, accessibility statement and HIPAA position are published on this site.

Third parties that process institutional data

  • Microsoft Azure — hosting
  • Elastic Cloud — reporting index
  • Radar — geofence evaluation
  • Google Firebase — push notifications, crash reporting and usage analytics using pseudonymous identifiers
  • Twilio SendGrid — transactional email
  • Freshdesk — support tickets

All are US-hosted. Where your institution enables it, duty hours are exported to your own residency management system. Each third party is assessed under our Third-Party Management Policy.

Reporting a security concern

Email security@resqmedical.com, or use the contact in our security.txt file. We acknowledge every report and keep the reporter informed. Please do not include patient or personal data in a report.

Reviewing ResQ for your institution?

Program status and policy documents are available to customers under NDA on request. A short demo shows how automatic duty-hour recording works for residents, coordinators and the GME office.

Request a demo