Data handling
How patient data is handled in the client portal, and what is and is not published on this site.
Where records go
Patient records stay inside the case channel.
Send records as they come. Identifiers belong with the case, inside the HIPAA-covered channel, and outside it a case travels on its case ID.
Nothing patient-identifying is published.
Every image on this site was checked by eye before publication. Clinical photography is published only with written patient authorization.
No patient identifiers in logs, analytics, invoices or URLs.
Agreements
An AWS Business Associate Agreement is in place, and one with your practice or laboratory is signed before any case carries records.
That covers the design work, which is what I provide.
Storage
Encrypted in transit and at rest.
On US AWS infrastructure, under that BAA. Files never move through personal file-sharing accounts, and never through servers outside the United States.
Retention runs for the duration of the engagement.
Deletion requests are honoured.
Related
Questions about the BAA, storage or file handling, ask before you send anything.