Security & Compliance

Enterprise-grade security and HIPAA compliance built for DSOs and group practices

HIPAA Compliant

Full HIPAA compliance with Business Associate Agreement (BAA) available for all customers

Role-Based Access Control

Granular permissions system ensuring least-privilege access across your organization

Comprehensive Audit Logging

Complete audit trail of all PHI access, modifications, and system actions for compliance

Single Sign-On (SSO)

Enterprise SSO integration with SAML 2.0 for streamlined, secure authentication

Data Encryption

End-to-end encryption for data in transit (TLS 1.3) and at rest (AES-256)

SOC 2 Type II

SOC 2 Type II compliance in progress, demonstrating operational security controls

Secure PMS Integrations

Least-Privilege PMS Integration

Read-only access where possible; write operations limited to scheduling and approved workflows

Secure API Architecture

OAuth 2.0, API key rotation, rate limiting, and IP whitelisting for all integrations

Isolated Tenant Data

Logical data separation ensuring your practice data is never co-mingled with others

Security Controls & Procedures

Access Controls

  • Multi-factor authentication (MFA) support
  • Session timeout and forced re-authentication
  • IP-based access restrictions
  • Automatic account lockout after failed attempts

Data Protection

  • Automated backup with encryption
  • Disaster recovery with <24hr RTO
  • Secure data destruction protocols
  • De-identification tools for analytics

Monitoring & Response

  • 24/7 security monitoring
  • Incident response procedures
  • Breach notification protocols
  • Regular vulnerability scanning

Compliance Management

  • Annual HIPAA risk assessments
  • Employee security training
  • Vendor security reviews
  • Regular penetration testing

Questions About Our Security?

Our team is ready to answer your security questions and provide documentation for your review

Book Demo