Q3 operating snapshot: 1,180 practices · 97.1% first-pass clean claims See the numbers
Advance EMR

Security

Controls we can describe. Certifications we will not invent.

Healthcare buyers have heard “HIPAA compliant” used as decoration. This page lists how the product actually behaves, and the line we will not cross in a sales conversation.

The chart is the source of truth

Portal identity is a mapping onto an existing patient. Credentials for each clinic are stored encrypted. Clinical writes from AI wait for the signed-in clinician.

Access is named

Staff and patients authenticate with Fortify and Sanctum on the portal, with authenticator MFA. Revenue roles separate admin, biller, and viewer, and clinic assignment is explicit.

PHI access is recorded

The revenue workspace keeps a PHI access audit. The portal keeps a durable audit trail, including hard-fail when a request leaves the patient compartment.

Patients see what policy allows

Result values respect a clinic release delay. Provider-only notes stay hidden. Consent and marketing flags are visible to the clinic. Proxy grants follow the record.

Transport and abuse limits

Exports, messaging, and mobile login are rate limited. Backups can be encrypted and shipped without copying environment secrets. Webhooks for remits and card payments expect a shared secret.

What we will not imply

This site does not claim a completed SOC 2 or HITRUST examination. Enterprise buyers receive a control narrative and a BAA conversation, and we will say clearly where a control is still a target.