Privacy & data security
Patient records contain protected health information (PHI), and the app is built to safeguard it.
Your identified records stay in your practice
Section titled “Your identified records stay in your practice”Every identified patient record belongs to a single practice. Providers only ever see their own practice’s patients and births — identifiable data never crosses between practices, and this tenant isolation is enforced throughout the app.
Two things deliberately span practices, and neither carries PHI:
- Benchmarks compare your practice against a de-identified registry aggregate — no PHI, no BAA. You see how you compare, never another practice’s records.
- My birth history is your own cross-practice career log. It lists the births you’ve attended across practices without any patient identifiers.
Who can see what: roles
Section titled “Who can see what: roles”Access follows least-privilege roles inside each practice:
- Admin — full control of the practice, including settings and team membership.
- Provider — day-to-day access: may read and write records, but holds no admin rights. This is the default for a new self-service account.
- Viewer — read-only. May view the practice’s records but is denied every write surface (capture, signing, imports, export generation, settings, and team management). Reads are still recorded on the PHI audit trail.
- Scribe — a write-only ingest seat: may record births but reads nothing and manages nothing — no chart, roster, export, or settings access.
Signing in securely
Section titled “Signing in securely”- Automatic sign-out when idle — you’re signed out after a period of inactivity (15 minutes by default), so an unattended screen doesn’t stay open.
- Two-factor authentication — available to everyone and can be required for specific roles in a practice; when it’s on, you confirm a code after your password.
- Passkeys — participating practices can sign in with a passkey (Face ID, Touch ID, Windows Hello, or a security key) for phishing-resistant sign-in.
See Sign-in & security for how to set these up.
How PHI is protected
Section titled “How PHI is protected”- Encryption — sensitive patient fields (including name, date of birth, record number, phone, and notes) are encrypted at rest.
- Access controls — the roles above determine what each provider can see and do.
- Access logging — every access to a patient record is recorded on an internal audit trail for compliance. (This trail is an internal safeguard; it is not a customer-facing screen in the app.)
API keys
Section titled “API keys”If you connect an EHR or data partner to import births, each connection uses its own API key — a per-source bearer token you issue in Settings. Keys carry least-privilege scopes (grant only what a source needs), and any key can be revoked at any time, which immediately stops that system from importing.
Support is a non-PHI channel
Section titled “Support is a non-PHI channel”Our in-app support widget is for help with using the app. The app shows the notice “Please don’t include patient names or other PHI in your message.” — please follow it. Attachments are disabled in the support widget to help prevent accidental sharing of PHI, and your identity is verified to our support provider using Secure Mode (a server-signed identity, so no PHI is exposed to do it).
If you need to discuss something specific to a patient record, contact us and we’ll guide you to a safe way to do it.
Your data, and a lapsed subscription
Section titled “Your data, and a lapsed subscription”You can export your practice’s data at any time — a spreadsheet backup or a full-fidelity JSON export — and that export keeps working even if your subscription lapses, so your records are never held hostage. See Your data.
Questions
Section titled “Questions”For questions about our privacy practices or a Business Associate Agreement (BAA), contact support.