Your Data is Protected
Layered technical and operational safeguards help protect health data. Each practice remains responsible for its configuration, agreements, policies, and authorized users.
Layered technical and operational safeguards help protect health data. Each practice remains responsible for its configuration, agreements, policies, and authorized users.
Clerk
Authentication
Role-aware
Access
HTTPS
Transport
PHI-aware
Logging
Role-aware access, PHI-aware logging, and audit-oriented workflows support a practice's HIPAA program. Compliance also depends on configuration, agreements, policies, and operations.
Production web traffic uses HTTPS, and authenticated sessions are handled by Clerk. Sensitive data must remain inside approved application boundaries.
We collect only the data necessary to provide our services. You can request a copy of your data, ask us to delete it, or connect with your care team.
Application records are designed for practice-aware authorization and least-privilege access. Practices must validate their own roles and staff access before go-live.
Account, export, correction, and deletion requests are handled through documented operational workflows and applicable retention requirements.
Automated checks, dependency review, audit logging, and release gates help identify regressions. No technical control replaces practice governance or incident response.
Production web traffic uses HTTPS and authenticated access
Patient and clinician entry paths are separated before onboarding
Role-aware controls are applied to protected application workflows
PHI-aware logging reduces sensitive-data exposure in operational logs
Security and dependency checks are part of the release process
Data-rights requests follow documented identity and retention checks
Practices must review staff roles, agreements, policies, and vendor configuration before go-live
We take security seriously. Reach out to our team for detailed information about our security practices.