Home → Security
What we do with your patients' data
Plain language, no security theatre. Here is exactly how DrinCloud handles protected health information, and what we have not done yet.
Business Associate Agreement
Under HIPAA we are your Business Associate. We sign a BAA with every practice at onboarding, at no cost, before any patient data exists in your account.
Encryption
Data is encrypted in transit with TLS and at rest in the database and in file storage. Each client runs on its own private cloud instance.
Audit log
Every view, edit, deletion and export is recorded with the user and timestamp, and you can download the log yourself from the Systems menu.
Access control
Granular permission profiles per role, optional IP restriction so some staff can only log in from the clinic, and automatic session timeout.
Backups & continuity
Automatic backups with restore procedures, plus continuous updates delivered without downtime or version upgrades on your side.
Breach notification
If a breach affecting your data ever occurred, we notify you without unreasonable delay so you can meet your own 60-day HIPAA obligation to patients and HHS.
What we have not done yet
Vendors in this market tend to imply certifications they do not hold. Ours, precisely:
- No ONC certification. It is a voluntary program and it is not required to run a cash-pay practice legally. It matters if you join Medicare incentive programs.
- No SOC 2 report yet. Small practices normally ask for the BAA; larger groups ask for SOC 2. If you need it, ask us where we are before you buy.
- No e-prescribing and no EPCS. If you prescribe controlled substances you will need a separate certified platform.
- No electronic claims to payers. We generate superbills; we do not transmit 837 claims to a clearinghouse.
Security questions
Do you sign a BAA?
Yes, with every practice, at no extra cost, as part of onboarding and before you enter a single patient record.
Where is the data hosted?
On Microsoft Azure infrastructure, with a private cloud instance per client and automatic backups.
Are you ONC certified?
No, and for a cash-pay practice it is not required. ONC certification is a voluntary program that matters for Medicare incentive programs such as MIPS.
Are you SOC 2 certified?
Not yet. We are transparent about that. If your organization requires a SOC 2 report before purchase, contact us and we will tell you honestly where we are.
Who can see clinical notes?
Only the roles you allow. Front-desk staff can be limited to scheduling and billing with no access to clinical content, and every view is recorded in the audit log.
Can I get my data out?
Always. Patients, appointments, invoices and reports export to CSV from inside the software at any time. A complete database export prepared by our engineers is available as a paid service.
Questions a checklist cannot answer?
Send them over. If the fit is bad, you will hear it from us before you pay a cent.