Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Back to About
Joseph A. Perrin

The Security Architect · CTO

Joseph A. Perrin

Infrastructure Architect

LinkedIn
The same threat actors we built defenses against in government were pivoting to small practices. And nobody had built the wall yet.

Joseph A. Perrin is the Chief Technology Officer of Patient Protect and the architect behind the platform's security infrastructure. His career spans federal and government-adjacent technology environments where the operational cost of a security failure is not measured in fines, but in mission compromise.

He designed and built the security foundation that every Patient Protect module runs on: a zero-trust architecture with AES-256-GCM encryption, a session vault that isolates each authenticated session from the broader application state, TLS 1.3 for all transport, fail2ban intrusion response, SMS-based two-factor authentication, an Altcha proof-of-work challenge layer against automated abuse, and browser-fingerprinting defense against credential-stuffing and session-hijacking attacks. The same architectural patterns he applied to protect government-sensitive systems now protect the patient data of independent clinical practices.

His methodology contribution runs deeper than the infrastructure itself. Patient Protect's risk-analysis model, threat-modeling framework, and Business Associate contract-review process reflect the federal discipline he brings to environments where documentation-only compliance was never sufficient. The platform's AppSensor integration and continuous audit logging are direct extensions of how he thinks about security: assume compromise, verify continuously, preserve evidence.

He works on ongoing platform hardening, vulnerability response, and the continuous review of every new component that enters the Patient Protect data path — from third-party integrations to internal features that touch ePHI.

Current focus

  • Security architecture across all Patient Protect modules
  • Encryption, session management, and audit logging infrastructure
  • Third-party integration and Business Associate technical review
  • Continuous hardening against credential-stuffing and session-hijacking

Areas of expertise

  • Zero-trust architecture and network segmentation for regulated environments
  • Encryption standards (AES-256-GCM at rest, TLS 1.3 in transit) and session security
  • Intrusion detection and automated response (fail2ban, AppSensor, browser-fingerprinting)
  • Multi-factor authentication and identity assurance for clinical workforces
  • Threat modeling and risk-analysis methodology for healthcare data environments
  • Business Associate Agreement contract review and third-party risk assessment
  • Federal and government-adjacent healthcare infrastructure security
  • Ongoing platform vulnerability response, hardening, and evidence preservation

Credentials & experience

  • Secure Infrastructure Architect — Federal & Clinical Healthcare Systemsprofessional experience
  • Zero-Trust Architecture — Platform Design and Implementationprofessional experience

Authored guides

Published by Joseph A. Perrin

7 guides on Patient Protect.

HIPAA incident response plan template for independent healthcare practices
Security & Threats·2026-07-31

HIPAA Incident Response Plan Template (2026)

The 9 sections every HIPAA incident response plan must contain under §164.308(a)(6), the 72-hour decision flow, and the template practices actually use — written by independent providers, not by Fortune 500 CISOs.

Network firewall comparison for HIPAA compliance in independent healthcare practices
Security & Threats·2026-06-26

Best Firewalls for HIPAA Compliance (2026)

HIPAA does not name a firewall. It names the controls a firewall must enforce. Six options ranked for independent practices — SonicWall, Fortinet, Cisco Meraki, pfSense, Palo Alto, WatchGuard.

Business Associate Agreement red flags that independent healthcare practices miss before signing
Compliance Operations·2026-04-05

Top 6 BAA Red Flags Every Independent Practice Misses

The six clauses in a Business Associate Agreement that determine whether the contract actually protects the practice or just satisfies the HIPAA box-check. What to read for before signing.