Skip to main content

Security & Privacy

The Practice Web Portal and PatientConnection are built for healthcare, where the contents of a single message can be protected health information. This page summarizes the protections that are always on, and the ones your practice can configure.

Account security

  • Invitation-only accounts. Staff accounts are created only by a practice administrator's invitation, and every person sets their own password from an emailed link — passwords are never issued or known by anyone else.
  • Passkeys and multi-factor sign-in. Every staff account supports passkeys (fingerprint, face, device PIN, or hardware key) and authenticator apps, with one-time recovery codes as a backup. See Signing In.
  • Office-network awareness and per-user remote access. A practice can register its office networks; staff then sign in normally at the office, while sign-in from anywhere else requires both an explicit per-user remote-access grant and a second factor. Second factors can only be added or removed from the office network, and a session that relied on the office network ends as soon as it is used from outside it.
  • Automatic lockout. Repeated failed sign-ins lock the account and notify the practice's administrators; persistent lockouts require an administrator to unlock.
  • Session timeouts. Idle sessions are signed out automatically (the timeout is a practice setting); patient portal sessions also have a maximum length.

Data protection

  • Attachment sanitizing. Every file that arrives from outside the practice — email attachments, patient uploads, faxes, picture messages — is opened in an isolated sandbox and rebuilt as a flat PDF before any staff member can view it. The original file is quarantined and never opened on a staff computer, so document-borne malware never reaches your practice. Files a staff member chooses to send are delivered unmodified.
  • Encryption. Data is encrypted in transit (HTTPS everywhere) and at rest, and practice email can be authenticated as the practice's own domain (SPF/DKIM).
  • Per-practice isolation. Each practice's hosted clinical data is kept in its own isolated database area with its own database credentials — isolation is enforced by the database itself, not just by application code.
  • Backups. Encrypted backups are taken automatically every day.

Accountability

  • Audit trail. Sign-ins, security changes, staff actions on patient data, and every patient portal request are recorded in a practice-wide audit log.
  • Administrator controls. Administrators can deactivate accounts immediately, reset a staff member's second factor, forget trusted browsers, and control per-user remote access and feature permissions — see Managing Staff Access.

HIPAA

IntelliPract® and PatientConnection are designed to support HIPAA compliance, and a Business Associate Agreement is available — see the Business Associate Agreement and our Privacy Policy. Compliance is a shared responsibility: your practice's own policies, staff training, and configuration choices (such as enabling second factors and restricting remote access) complete the picture.