Security & product scope

Clear current-state boundaries are part of good security.

PracticeOps currently operates as a non-PHI workspace for medical-practice operations.

Requires security and legal review. Verify these statements against the production environment and customer agreements before launch.

Current data boundary

Use PracticeOps for operational data only for now. Keep patient-identifying and clinical information in athenahealth or the source system until PHI-enabled integrations are formally supported.

Application controls

The current product includes role-based access, organization-level separation, controlled onboarding, secure password handling, session controls, and audit history. Exact implementation and hosting details must be verified for each production environment.

Integration status

Athena-style integration simulation is available for evaluation with synthetic events. Live athenahealth connectivity is not yet enabled. No athenahealth certification, endorsement, Marketplace approval, or production data connection is claimed.

Future data use

Future integrations may require limited patient or appointment data to support operational workflows. Any PHI-enabled functionality will be introduced only with appropriate privacy, security, technical, and contractual controls in place.

No unsupported certification claims

CareContact does not currently claim HIPAA compliance, SOC 2 certification, HITRUST certification, penetration-test certification, or BAA availability on this website.

Report a concern

Use the contact page to report a security concern without including patient-identifying, clinical, or other sensitive information. A dedicated security contact and incident-response process require human confirmation before launch.