Security

How access is controlled.

What a practice's security or privacy review asks first, on one page.

Access and isolation

Practice isolation.One practice cannot see another practice's data. Every request is scoped to the practice on the signed-in account's token.

Facility-scoped access. Within a practice, an account is granted access facility by facility. A clinician without a broader assignment sees only the patients and encounters tied to the facilities they are granted.

Roles. Four roles: owner, admin, clinician, and billing. Each sees the parts of the workspace built for that job.

Sign-in. Sign-in uses an email address and a password, and supports a second factor. A session that goes idle requires signing back in, including any enrolled second factor, before it continues.

Audit trail. Every time patient information is read or written, an entry is recorded: who, when, and what was touched. Entries cannot be edited or deleted.

Data protection

Encryption. Data is encrypted in transit and at rest.

Removing a facility. A removed facility is held in a recoverable state for 30 days before it is permanently deleted.

Coding and billing exports.Confirmed codes and the excerpt that supports each one export to CSV or PDF, or copy to your clipboard, for your practice's own billing workflow.

Development and testing

Development and test environments run on synthetic data. No real patient information is used to build or test a new feature before it reaches a practice.

Contact

Questions about a specific control, or a vulnerability to report, go to security@prosemed.ai.