Security & HIPAA

Security is not a feature we charge extra for

You are handing us protected health information. These are the controls that sit around it.

Encryption

TLS for everything in transit and encryption at rest for the database and backups.

Role-based access

Permissions granted by role down to the module, so front desk staff don't see clinical notes they have no reason to open.

Two-factor authentication

Available for every user and strongly recommended for anyone with administrative rights.

Audit trail

Every record access and change is logged with user, timestamp and action, and the log is reviewable.

Backups

Automated encrypted backups with documented restore procedures that get tested rather than assumed.

Business Associate Agreement

A signed BAA is part of onboarding for every practice, covering both the software and the billing service.

Session controls

Idle session timeouts and forced password complexity, so an unattended workstation isn't an open chart.

Your data is yours

You can export your complete patient data in standard formats at any time, including if you leave us.

Trained staff

Our billing team works inside HIPAA every day and is trained on minimum-necessary access and breach reporting.

Questions your compliance officer will ask

We'd rather answer them before you sign than after. Ask us for our BAA, our access-control documentation and our backup and restore procedure, and we'll send them.