Security & Compliance

Your patients' data deserves the highest standard of protection. We build security into everything we do.

HIPAA Compliant

  • Business Associate Agreement (BAA) signed on Day 1
  • All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Regular security training for all team members

Access Controls

  • Role-based access for coordinators and administrators
  • Audit logging for all patient data access
  • Multi-factor authentication supported

Infrastructure

  • Hosted on enterprise-grade cloud infrastructure
  • Continuous monitoring and automated backups
  • Encryption in transit (TLS) and at rest (AES-256)

Data Handling

  • Patient data retained per your facility's policy
  • Data export and deletion available on request
  • No data sold or shared with third parties

Certifications

  • PointClickCare Certified Development Partner
  • HIPAA compliant — BAA signed on Day 1

Transparency

  • Scoped PCC integration — pulls patient profile fields and writes progress notes; never pulls clinical documentation
  • Clear data processing agreements
  • Security practices available upon request
PointClickCare Certified Development PartnerCertified Development Partner

Questions about security? Contact us at security@maxmrj.com