Security is not a feature we charge extra for
You are handing us protected health information. These are the controls that sit around it.
Encryption
TLS for everything in transit and encryption at rest for the database and backups.
Role-based access
Permissions granted by role down to the module, so front desk staff don't see clinical notes they have no reason to open.
Two-factor authentication
Available for every user and strongly recommended for anyone with administrative rights.
Audit trail
Every record access and change is logged with user, timestamp and action, and the log is reviewable.
Backups
Automated encrypted backups with documented restore procedures that get tested rather than assumed.
Business Associate Agreement
A signed BAA is part of onboarding for every practice, covering both the software and the billing service.
Session controls
Idle session timeouts and forced password complexity, so an unattended workstation isn't an open chart.
Your data is yours
You can export your complete patient data in standard formats at any time, including if you leave us.
Trained staff
Our billing team works inside HIPAA every day and is trained on minimum-necessary access and breach reporting.
Questions your compliance officer will ask
We'd rather answer them before you sign than after. Ask us for our BAA, our access-control documentation and our backup and restore procedure, and we'll send them.