Security & Privacy
The Practice Web Portal and PatientConnection are built for healthcare, where the contents of a single message can be protected health information. This page summarizes the protections that are always on, and the ones your practice can configure.
Account security
- Invitation-only accounts. Staff accounts are created only by a practice administrator's invitation, and every person sets their own password from an emailed link — passwords are never issued or known by anyone else.
- Passkeys and multi-factor sign-in. Every staff account supports passkeys (fingerprint, face, device PIN, or hardware key) and authenticator apps, with one-time recovery codes as a backup. See Signing In.
- Office-network awareness and per-user remote access. A practice can register its office networks; staff then sign in normally at the office, while sign-in from anywhere else requires both an explicit per-user remote-access grant and a second factor. Second factors can only be added or removed from the office network, and a session that relied on the office network ends as soon as it is used from outside it.
- Automatic lockout. Repeated failed sign-ins lock the account and notify the practice's administrators; persistent lockouts require an administrator to unlock.
- Session timeouts. Idle sessions are signed out automatically (the timeout is a practice setting); patient portal sessions also have a maximum length.
Data protection
- Attachment sanitizing. Every file that arrives from outside the practice — email attachments, patient uploads, faxes, picture messages — is opened in an isolated sandbox and rebuilt as a flat PDF before any staff member can view it. The original file is quarantined and never opened on a staff computer, so document-borne malware never reaches your practice. Files a staff member chooses to send are delivered unmodified.
- Encryption. Data is encrypted in transit (HTTPS everywhere) and at rest, and practice email can be authenticated as the practice's own domain (SPF/DKIM).
- Per-practice isolation. Each practice's hosted clinical data is kept in its own isolated database area with its own database credentials — isolation is enforced by the database itself, not just by application code.
- Backups. Encrypted backups are taken automatically every day.
Accountability
- Audit trail. Sign-ins, security changes, staff actions on patient data, and every patient portal request are recorded in a practice-wide audit log.
- Administrator controls. Administrators can deactivate accounts immediately, reset a staff member's second factor, forget trusted browsers, and control per-user remote access and feature permissions — see Managing Staff Access.
HIPAA
IntelliPract® and PatientConnection are designed to support HIPAA compliance, and a Business Associate Agreement is available — see the Business Associate Agreement and our Privacy Policy. Compliance is a shared responsibility: your practice's own policies, staff training, and configuration choices (such as enabling second factors and restricting remote access) complete the picture.