Practices are isolated from each other
One practice's data is never visible from another's. The boundary holds whatever anyone clicks, because it is not a setting somebody has to remember to apply.
Security and compliance
Halcora handles protected health information, so the controls are structural rather than procedural. What follows is implemented, not aspired to.
One practice's data is never visible from another's. The boundary holds whatever anyone clicks, because it is not a setting somebody has to remember to apply.
Everything you send us is encrypted while it travels and encrypted where it is stored, backups included.
Every touch is appended to the record. A correction adds what changed without erasing what came before, and a look at protected health information is recorded as well as a change to it.
Access is given per practice and per function. Somebody working one practice cannot see another, and a grant can be withdrawn as explicitly as it was made.
Every document you upload is checked before it is stored or made available to anyone.
Stored and processed in the United States, backups included. We will name the hosting regions and give you the subprocessor list on request.
Will you sign a business associate agreement? Yes, and it is in place before any real protected health information is handled.
Where does our data sit? In the United States. We will name the regions, the hosting provider and every subprocessor on request.
Can we see your controls documentation? Yes, under a mutual non-disclosure agreement. Ask and we will send the current package.
We would rather answer security questions early. Tell us what your review requires and we will share the available controls documentation under a mutual non-disclosure agreement.