Three layers of data protection
DocNow's security architecture maps to the administrative, technical, and physical safeguard categories specified in the HIPAA Security Rule — covering access management, encryption, and audit accountability.
Access Controls
Role-based access controls limit data visibility to the minimum necessary for each user's function. Multi-factor authentication is required for all clinical user accounts. Session timeouts and automatic logout protect unattended devices.
Data Encryption
Patient data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Database access is restricted to application-layer connections — direct database queries are blocked at the network level. Backup data carries the same encryption standard.
Audit Logging
Every access, edit, and deletion of patient records is logged with user identity, timestamp, and IP address. Audit logs are retained for a minimum of 6 years per HIPAA requirements. Administrators can review access logs at any time.
Our approach to HIPAA compliance
DocNow is designed with HIPAA compliance controls built into the platform architecture. We are not HIPAA certified — no such official certification program exists under HHS — but our platform is built to support covered entities and their business associates in meeting obligations under the HIPAA Privacy Rule and Security Rule.
We execute a Business Associate Agreement (BAA) with every healthcare provider customer as part of the onboarding process. Our security controls are documented, reviewed on a scheduled basis, and periodically assessed by third-party security reviewers. If your organization requires a review of our controls documentation before contract, contact us directly.
Security questions or BAA requests: [email protected] or +1 (615) 244-1122.
Business Associate Agreement
DocNow executes a BAA with every healthcare provider customer as part of the onboarding process.
Third-Party Security Reviews
We engage third-party security assessors to review our technical controls and incident response procedures.
Incident Response
Documented breach notification and incident response procedures aligned with HIPAA Breach Notification Rule requirements.
Questions about our security program?
Talk to a DocNow specialist about our BAA, access controls, and security documentation.