Skip to content

Privacy & data security

Patient records contain protected health information (PHI), and the app is built to safeguard it.

Your identified records stay in your practice

Section titled “Your identified records stay in your practice”

Every identified patient record belongs to a single practice. Providers only ever see their own practice’s patients and births — identifiable data never crosses between practices, and this tenant isolation is enforced throughout the app.

Two things deliberately span practices, and neither carries PHI:

  • Benchmarks compare your practice against a de-identified registry aggregate — no PHI, no BAA. You see how you compare, never another practice’s records.
  • My birth history is your own cross-practice career log. It lists the births you’ve attended across practices without any patient identifiers.

Access follows least-privilege roles inside each practice:

  • Admin — full control of the practice, including settings and team membership.
  • Provider — day-to-day access: may read and write records, but holds no admin rights. This is the default for a new self-service account.
  • Viewer — read-only. May view the practice’s records but is denied every write surface (capture, signing, imports, export generation, settings, and team management). Reads are still recorded on the PHI audit trail.
  • Scribe — a write-only ingest seat: may record births but reads nothing and manages nothing — no chart, roster, export, or settings access.
  • Automatic sign-out when idle — you’re signed out after a period of inactivity (15 minutes by default), so an unattended screen doesn’t stay open.
  • Two-factor authentication — available to everyone and can be required for specific roles in a practice; when it’s on, you confirm a code after your password.
  • Passkeys — participating practices can sign in with a passkey (Face ID, Touch ID, Windows Hello, or a security key) for phishing-resistant sign-in.

See Sign-in & security for how to set these up.

  • Encryption — sensitive patient fields (including name, date of birth, record number, phone, and notes) are encrypted at rest.
  • Access controls — the roles above determine what each provider can see and do.
  • Access logging — every access to a patient record is recorded on an internal audit trail for compliance. (This trail is an internal safeguard; it is not a customer-facing screen in the app.)

If you connect an EHR or data partner to import births, each connection uses its own API key — a per-source bearer token you issue in Settings. Keys carry least-privilege scopes (grant only what a source needs), and any key can be revoked at any time, which immediately stops that system from importing.

Our in-app support widget is for help with using the app. The app shows the notice “Please don’t include patient names or other PHI in your message.” — please follow it. Attachments are disabled in the support widget to help prevent accidental sharing of PHI, and your identity is verified to our support provider using Secure Mode (a server-signed identity, so no PHI is exposed to do it).

If you need to discuss something specific to a patient record, contact us and we’ll guide you to a safe way to do it.

You can export your practice’s data at any time — a spreadsheet backup or a full-fidelity JSON export — and that export keeps working even if your subscription lapses, so your records are never held hostage. See Your data.

For questions about our privacy practices or a Business Associate Agreement (BAA), contact support.