Security & product scope
Clear current-state boundaries are part of good security.
PracticeOps currently operates as a non-PHI workspace for medical-practice operations.
Current data boundary
Use PracticeOps for operational data only for now. Keep patient-identifying and clinical information in athenahealth or the source system until PHI-enabled integrations are formally supported.
Application controls
The current product includes role-based access, organization-level separation, controlled onboarding, secure password handling, session controls, and audit history. Exact implementation and hosting details must be verified for each production environment.
Integration status
Athena-style integration simulation is available for evaluation with synthetic events. Live athenahealth connectivity is not yet enabled. No athenahealth certification, endorsement, Marketplace approval, or production data connection is claimed.
Future data use
Future integrations may require limited patient or appointment data to support operational workflows. Any PHI-enabled functionality will be introduced only with appropriate privacy, security, technical, and contractual controls in place.
No unsupported certification claims
CareContact does not currently claim HIPAA compliance, SOC 2 certification, HITRUST certification, penetration-test certification, or BAA availability on this website.
Report a concern
Use the contact page to report a security concern without including patient-identifying, clinical, or other sensitive information. A dedicated security contact and incident-response process require human confirmation before launch.