Data handling
The posture today.

- Each practice is its own tenant. No shared patient pool and no cross-tenant read.
- Clinical data is fenced at the database, not in application code, so a bug in a page cannot read around it.
- Page access is a role stored as data; an unrecognized role ranks lowest, so a typo costs access rather than granting it.
- Call recordings and clinical media are held apart from operational data.
- No bank account number is stored in any tenant.
In progress
Named rather than implied.
The business associate agreement program and the vendor agreements underneath it are being completed ahead of the founding cohort. Until then, clinical features are fenced off for medical practices rather than quietly enabled.
We will publish the signed specifics here when they exist.
How to evaluate any vendor on this
Ask for the business associate agreement and the subprocessor list by name, and ask when each was last updated. The speed and specificity of the answer tells you more than the documents do.