Trust & Security
Built so patient information stays where it belongs
We coordinate care. Clinicians keep the medical record. This page explains, plainly, how information moves through our platform, what we protect, and where our responsibility ends and a clinician's begins.
How it is designed
A coordination platform, not a medical record
The simplest way to protect clinical information is to not hold it. That choice shapes everything else below.
Coordination layer
Our platform handles logistics: scheduling, caregiver matching, visit verification, and connecting a patient to a clinician at the bedside.
No clinical record of our own
We do not maintain a medical record. Participating clinicians document in their own certified record system and bill under their own credentials.
Least information necessary
Each role sees only what the work requires. Caregivers see their own assignments; coordinators see the clients they support.
Safeguards
What is in place today
Each item here is already part of how our portals work.
Role-based access
Every account is tied to a role, and access rules are enforced by the database itself rather than by the screen a person happens to open.
Logged activity
Sign-ins, record views, and document downloads are recorded so access can be reviewed.
Session limits
Sessions lock after 15 minutes of inactivity and require signing in again at least every 12 hours — important on shared devices.
Verified identity for providers
Provider accounts sign in with an organization email and confirm a one-time emailed code before reaching the workspace.
Encrypted connections
All traffic to and from this site and our portals is served over HTTPS, and stored data is encrypted by our hosting provider.
Private portals stay private
Client, caregiver, provider, and staff areas require sign-in and are excluded from search engines.
Shared responsibility
Who is accountable for what
Practices and health systems ask this first. Here is the answer in writing.
What we are responsible for
- Screening and onboarding the caregivers we employ
- Scheduling, visit verification, and bedside setup for a virtual visit
- Enforcing role boundaries and keeping an access log
- Requiring a signed business associate agreement before any patient visit
What the clinician is responsible for
- All clinical judgment, diagnosis, and treatment decisions
- Documentation and retention in their own medical record system
- Billing under their own credentials
- Licensure, malpractice coverage, and the security of their own devices
Where we are honest about status
- Our Healthcare Access Network is a private beta. It is not open to the public, and no patient visits take place before the agreements below are signed.
- We hold no third-party security certifications today. If a certification becomes a requirement for a partner, we will say so plainly rather than imply one we do not have.
- Virtual visits require a video service that supports healthcare privacy rules under a signed agreement. Until that is executed with a partner practice, visits are not scheduled.
- Participating clinicians are independent and licensed. They remain responsible for the care they deliver.
Reviewing us as a partner or vendor?
Send your security questionnaire or agreement template and we will work through it directly. We would rather answer hard questions early than late.
Albany, Georgia · (229) 595-2921