Security & Compliance

Enterprise-grade security and HIPAA compliance built for DSOs and group practices

HIPAA Compliant

Full HIPAA compliance with Business Associate Agreement (BAA) available for all customers

Role-Based Access Control

Granular permissions system ensuring least-privilege access across your organization

Comprehensive Audit Logging

Complete audit trail of all PHI access, modifications, and system actions for compliance

Data Encryption

End-to-end encryption for data in transit (TLS 1.3) and at rest (AES-256)

Audit Logging

Complete audit trail of all system access, data modifications, and security events

Role-Based Access Control

Granular RBAC ensuring users only access the data and features they need

Secure PMS Integrations

Least-Privilege PMS Integration

Read-only access where possible; write operations limited to scheduling and approved workflows

Secure API Architecture

OAuth 2.0, API key rotation, rate limiting, and IP whitelisting for all integrations

Isolated Tenant Data

Logical data separation ensuring your practice data is never co-mingled with others

Security Controls & Procedures

Access Controls

  • Multi-factor authentication (MFA) support
  • Session timeout and forced re-authentication
  • IP-based access restrictions
  • Automatic account lockout after failed attempts

Data Protection

  • Automated backup with encryption
  • Disaster recovery with <24hr RTO
  • Secure data destruction protocols
  • De-identification tools for analytics

Monitoring & Response

  • 24/7 security monitoring
  • Incident response procedures
  • Breach notification protocols
  • Regular vulnerability scanning

Compliance Management

  • Annual HIPAA risk assessments
  • Employee security training
  • Vendor security reviews
  • Regular penetration testing

Questions About Our Security?

Our team is ready to answer your security questions and provide documentation for your review

Book Demo
Need help?