window.dataLayer = window.dataLayer || []; function gtag(){dataLayer.push(arguments);} gtag('js', new Date()); gtag('config', 'G-N1JDEYRGEY'); function allConsentGranted() { gtag('consent', 'update', { 'ad_user_data': 'granted', 'ad_personalization': 'granted', 'ad_storage': 'granted', 'analytics_storage': 'granted' }); } jQuery(document).ready(function(){ jQuery('a#cn-accept-cookie').click(function(){ allConsentGranted(); }) });

Security, Privacy and HIPAA

We handle protected health information, so this page states our posture directly rather than in badges.

How patient data is handled

  • Encryption in transit and at rest.
  • Role-based access control, so a user sees the records their role requires and not the rest.
  • Audit logging of access and of every clinical decision, attributable to an individual user.
  • Business Associate Agreements with the vendors that touch PHI on our behalf, including any AI-assisted tooling.
  • Tenant separation, so one client’s records are not visible to another.
  • Credentials held encrypted rather than in plain configuration.

What we do not claim

We do not advertise a SOC 2 report we have not completed, and you will not find that badge on this site. Several vendors in this market display audit logos they cannot produce a report for; ask any of them, including us, for the document rather than the image.

We also do not describe ourselves as “HIPAA certified”, because no such certification exists. HIPAA compliance is a posture and a set of agreements, not a certificate.

What we will give you in diligence

  • A signed Business Associate Agreement.
  • A description of the data flows for your specific integration.
  • Our subprocessor position for anything that touches your patients’ records.
  • Confirmation of what is retained, for how long, and what happens on termination.

Related

Book a call and we will walk your technical reviewer through it.