> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and PHI

> What the Partner API sends, how to store it, and what to do on exposure

Visit status webhooks include a **full referral snapshot**. That payload is PHI:
patient name, date of birth, contact, and clinical procedure detail.

Notification webhooks are metadata only. Recipients and message bodies are never
returned.

## Requirements

* Terminate TLS. Scan only accepts `https://` webhook URLs.
* Verify `X-Scan-Signature` (`v1=` HMAC-SHA256 of `{timestamp}.{raw body}`) and
  reject timestamps older than five minutes.
* During signing-secret rotation Scan may send multiple `v1=` signatures for 24
  hours. Accept if **any** matches.
* Do not log raw payloads, tokens, or signing secrets.
* Rotate the webhook secret from the API access tab. The previous secret is not
  displayed again.
* Use synthetic data only in the sandbox.

## Certifications and subprocessors

Scan maintains a **SOC 2 Type II** report. Email
[api@scan.com](mailto:api@scan.com) to request it. An NDA must be in place
before the report is shared.

Imaging studies are retrieved from **Ambra**, Scan's imaging-archive
subprocessor. Notification webhooks never include study bytes; DICOM downloads
go through the order-documents routes.

## IP allowlisting

Scan does not currently publish a static egress IP list for webhooks. Authenticate
with the signature, not the source address.

## BAAs, retention, and incident SLAs

Contractual BAA language, retention periods, and support response times are
issued by Security, Legal, and Support — they are not implied by this page.
Email [api@scan.com](mailto:api@scan.com) for the current packet.

If you suspect exposure of a Scan token or webhook secret, email
[api@scan.com](mailto:api@scan.com) with the `X-Request-Id` of a recent call and
revoke the credential from the API access tab.
