Skip to main content

Privacy & Security for Patients

Your portal account and everything in it are protected by design:

  • Your account is yours alone. Accounts are created only by your practice's invitation or by self-registration verified with your date of birth, and each account belongs to a single patient. You choose your own password; no one else knows it.
  • Strong sign-in. Long passwords are required, you can add a passkey (fingerprint, face, or device PIN), and repeated failed sign-in attempts lock the account and alert the practice.
  • Automatic sign-out. Idle sessions are signed out automatically, and portal sessions have a maximum length — useful on shared or family devices.
  • Encryption. Everything between your browser and the portal is encrypted (HTTPS), and your data is encrypted where it is stored.
  • Safe documents. Files exchanged through the portal are converted to clean, flattened PDFs in an isolated environment, protecting both you and the practice from document-borne malware.
  • Private notifications. Email notifications tell you something is waiting in the portal — they never include the message or document itself.
  • Card details stay with the processor. Online payments are entered directly with the payment processor; the portal never sees or stores your card number.
  • Everything is recorded. Every request made through your portal account is written to the practice's audit log, creating an accountable record of access to your information.

The service is designed to support HIPAA compliance. For the formal terms, see the Privacy Policy and the practice-facing Business Associate Agreement.