Skip to main content
Secure Texting

What is the Best Architecture for Secure Texting & Encrypted Messaging?

QliqSOFT’s “Security First” philosophy guides the design and management of its secure clinical collaboration platform. We’ve developed the Qliq encrypted messaging apps and platform from the ground up with security as the top priority. In the “HIPAA Omnibus Era,” healthcare organizations face challenging security risks from their partners and vendors in handling protected health information (PHI).

3 min read
best architecture for secure texting|encrypted messaging app for healthcare organizations

QliqSOFT’s “Security First” philosophy guides the design and management of its secure clinical collaboration platform. We’ve developed the Qliq encrypted messaging apps and platform from the ground up with security as the top priority. In the “HIPAA Omnibus Era,” healthcare organizations face challenging security risks from their partners and vendors in handling protected health information (PHI).At QliqSOFT, we have drastically reduced the security risk of a PHI breach by designing Qliq with a more robust security architecture on an enterprise-proven communication platform. Our three pillars of security achieve significant advantages over alternative messaging and collaboration solutions. It not only offers greater protection of patient information but also reduces motive, means and incentive for intruders.

Cloud Pass-Thru

First, Qliq uses a “Cloud Pass-Thru” messaging architecture, where encrypted messages pass from the sender through the Qliq Cloud server to the recipient. No large storage server keeps all the messages for all the Qliq users in the Cloud. Qliq’s “Cloud Pass-Thru” architecture is substantially more secure than legacy “client/server” architecture because no Protected Health Information (PHI) is stored or decrypted on the QliqSOFT servers. The client/server model commonly found is less secure since it involves decrypting, storing and logging of all messages on a 3rd party server.

Double Encryption

Second, Qliq is unique in that it uses an individual Public/Private Key Encryption model. Every Qliq user has a unique encryption key pair, and each message is encrypted specifically for the single recipient of the message. QliqSOFT has no access to the decryption keys (private keys).

encrypted messaging app for healthcare organizations

Therefore, it is impossible for QliqSOFT to decrypt messages in transit and cannot access your PHI. Since “Cloud Pass-Thru” is peer-to-peer, all messages are encrypted/decrypted only in the app on your mobile devices and computers. In effect, all messages and PHI is “double-encrypted” as the metadata is also encrypted using TLS/HTTPS Transport encryption during network transmission.

Archive in Your Control

Lastly, Qliq offers a secure encrypted messaging archive (auditing) solution called QliqSTOR that resides behind the customer’s firewall and in their direct control. QliqSOFT does not store the archive containing extensive PHI on its cloud server. This drastically reduces 3rd party vendor risk of a PHI breach and provides easier access for eDiscovery research by the administrator.

Reduced Risk and Easier Compliance

QliqSOFT’s security approach dramatically reduces the risk of a breach of PHI since we serve only as a conduit of encrypted information. Furthermore, the fact that QliqSOFT (and its sub-vendors) cannot decrypt and access PHI allows you to complete your HIPAA security and risk analysis of QliqSOFT, which is required by the HIPAA Omnibus Rule, in less time and with fewer resources. With alternative client-server communication solutions, you need more extensive due diligence on vendors and sub-vendors, depend more on vendor security and face more risk and uncertainty.Click Here to Learn More about HIPAA Security Compliance

Frequently Asked Questions

Find answers to common questions about this topic.

Cloud pass-through architecture routes encrypted messages directly from sender to recipient without storing or decrypting PHI on third-party servers. Traditional client-server systems decrypt, store, and log all messages on vendor servers, creating significantly higher security risks for healthcare organizations.

Double encryption combines individual public/private key encryption for each message recipient with TLS/HTTPS transport encryption during network transmission. This means both the message content and metadata are encrypted, with decryption only occurring on the end user's device.

QliqSTOR archives are stored behind the customer's own firewall under their direct control, not on vendor cloud servers. This approach reduces third-party vendor risk and provides healthcare organizations easier access for eDiscovery research and compliance audits.

When vendors cannot decrypt or access PHI, healthcare organizations can complete required HIPAA security and risk analyses faster with fewer resources. This eliminates the need for extensive due diligence on multiple sub-vendors and their security practices.

In properly designed systems like Qliq, vendors have no access to private decryption keys, making it impossible for them to decrypt messages in transit. This peer-to-peer encryption model ensures only the intended recipient can access PHI content.

Ben Henson

Written by

Ben Henson

Healthcare IT Specialist

Healthcare IT specialist with expertise in HIPAA compliance and secure messaging.

View all posts

Related Articles

replace healthcare pagers with secure texting|
Secure Texting

Secure Texting for Pager Replacement

According to a HIMSS research study, over 90% of hospitals still, rely on pagers to coordinate patient care. Unfortunately, this antiquated technology provides only a one-way means of communication, where nurses must waste precious time waiting for a physician to respond to their page and never knowing if they ever received it. That is why we developed Qliq, the best secure texting platform and pager replacement solution that connects doctors and nurses and facilitates true patient-centered communication.

Ben HensonBen Henson
2 min read
patient doctor relationships via secure texting|secure texting for smartphones enhance patient doctor relationships
Secure Texting

How HIPAA Texting Apps Will Change Patient-Doctor Relationships

Everyone is using multiple instant messaging apps these days. People around the world are embracing the idea of this quick, and easy way of communication with the health care provider. But, when it is linked with facilitating the patients with a desirable alternative, such as texting, to communicate with the physicians, it accompanies the risk of data privacy issues even for the doctors who try to stay HIPAA compliant.

Ben HensonBen Henson
3 min read
3m left