Security and compliance

Built for the review before it happens

Halcora handles protected health information, so the controls are structural rather than procedural. What follows is implemented, not aspired to.

Talk to us

What we guarantee about your data

Practices are isolated from each other

One practice's data is never visible from another's. The boundary holds whatever anyone clicks, because it is not a setting somebody has to remember to apply.

Encrypted in transit and at rest

Everything you send us is encrypted while it travels and encrypted where it is stored, backups included.

Corrections preserve the history

Every touch is appended to the record. A correction adds what changed without erasing what came before, and a look at protected health information is recorded as well as a change to it.

People reach only what they were granted

Access is given per practice and per function. Somebody working one practice cannot see another, and a grant can be withdrawn as explicitly as it was made.

Uploaded files are checked first

Every document you upload is checked before it is stored or made available to anyone.

Your data stays in the United States

Stored and processed in the United States, backups included. We will name the hosting regions and give you the subprocessor list on request.

What procurement actually asks

Will you sign a business associate agreement? Yes, and it is in place before any real protected health information is handled.

Where does our data sit? In the United States. We will name the regions, the hosting provider and every subprocessor on request.

Can we see your controls documentation? Yes, under a mutual non-disclosure agreement. Ask and we will send the current package.

Start with the security review

We would rather answer security questions early. Tell us what your review requires and we will share the available controls documentation under a mutual non-disclosure agreement.

Talk to us