Security

How access is controlled.

What a practice's security or privacy review asks first, on one page.

Access and isolation

Practice isolation.One practice cannot see another practice's data. Every request is scoped to the practice on the signed-in account's token.

Facility-scoped access. Within a practice, an account is granted access facility by facility. A clinician without a broader assignment sees only the patients and encounters tied to the facilities they are granted.

Roles. Access is granted by role, so a clinician, a coder, a biller and an administrator each reach only the work their job needs.

Sign-in. Sign-in uses an email address and a password, with support for multi-factor authentication. A session that goes idle requires signing back in, including any enrolled factor, before it continues.

Audit trail. Every time patient information is read or written, an entry is recorded: who, when, and what was touched. Entries cannot be edited or deleted.

Data protection

Encryption. Data is encrypted in transit and at rest.

Removing a facility. A removed facility is held in a recoverable state for 30 days before it is permanently deleted.

Coding and billing exports.Confirmed codes and the excerpt that supports each one export to CSV or PDF for your practice's own billing.

Contact

Questions about a specific control, or a vulnerability to report, go to [email protected].