Security and privacy posture

This page says what is actually in place and what is not. It names no certification, because we hold none.

What is in place

We design with HIPAA considerations in mind. Our infrastructure runs on AWS with encryption at rest and in transit, role-based access controls, and each clinic's data isolated from every other.

What is not in place, stated plainly

  • No authority certifies anyone under HIPAA. There is no such credential to hold, so no vendor can hold one, and we claim none. If you are comparing vendors and one of them says otherwise, that is worth a question.
  • We hold no SOC 2 report. If that changes, this page changes with it.
  • We give no date for any of the above. A timeline is a promise about someone else's queue.

What we never ask you for

  • No chart upload during a walkthrough. The fifteen minutes runs on sample charts. There is no upload path on this website at all.
  • No patient information in any form on this site. If you are about to paste chart text into a contact form, stop - we do not need it and we do not want it.
  • No login, no trial, no account before an engagement is agreed.

How findings are handled

Output is advisory. The software does not tell a provider what the code should be; it surfaces what is worth a second look, and a person decides. Every suggestion carries the evidence it rests on and the reasoning behind it, and every decision is recorded with the person who made it.

Book the 15 Minutes