Skip to main content
Security & Compliance

Your Data is Protected

Layered technical and operational safeguards help protect health data. Each practice remains responsible for its configuration, agreements, policies, and authorized users.

Clerk

Authentication

Role-aware

Access

HTTPS

Transport

PHI-aware

Logging

HIPAA-Aligned Safeguards

Role-aware access, PHI-aware logging, and audit-oriented workflows support a practice's HIPAA program. Compliance also depends on configuration, agreements, policies, and operations.

Encrypted Transport

Production web traffic uses HTTPS, and authenticated sessions are handled by Clerk. Sensitive data must remain inside approved application boundaries.

Privacy by Design

We collect only the data necessary to provide our services. You can request a copy of your data, ask us to delete it, or connect with your care team.

Tenant-Aware Architecture

Application records are designed for practice-aware authorization and least-privilege access. Practices must validate their own roles and staff access before go-live.

Data Rights Workflows

Account, export, correction, and deletion requests are handled through documented operational workflows and applicable retention requirements.

Security Review

Automated checks, dependency review, audit logging, and release gates help identify regressions. No technical control replaces practice governance or incident response.

How We Handle Your Data

Production web traffic uses HTTPS and authenticated access

Patient and clinician entry paths are separated before onboarding

Role-aware controls are applied to protected application workflows

PHI-aware logging reduces sensitive-data exposure in operational logs

Security and dependency checks are part of the release process

Data-rights requests follow documented identity and retention checks

Practices must review staff roles, agreements, policies, and vendor configuration before go-live

Questions About Security?

We take security seriously. Reach out to our team for detailed information about our security practices.