Skip to content

EHR security

EHR security and HIPAA: how EzPraxis protects your data.

The questions your compliance reviewer will ask, answered with the safeguards EzPraxis actually has: where data lives, who can see it, what gets logged, and the BAA.

HIPAA and EzPraxis.

There is no official HIPAA certification for software, and compliance depends on how a practice works, not only on the systems it uses. What a vendor can do is provide the safeguards and offer the Business Associate Agreement that HIPAA requires. This is what EzPraxis provides.

  • Hosted on AWS in the United States

    The application runs on Amazon Web Services in the U.S.: Amazon ECS for the application, a SQL Server database, Amazon S3 for documents, Amazon Cognito for staff sign-in and Amazon SES for email. Each new practice gets its own isolated database.

  • Encrypted in transit

    Every connection uses HTTPS, with HSTS so that browsers never fall back to an unencrypted connection.

  • Role-based access

    Eight built-in roles and about 95 permissions, each scoped to a user’s own clients, their supervisees or the whole practice, and assigned by location. One person can hold several roles.

  • Two-step verification for staff

    Staff can confirm their sign-in with an authenticator app or an emailed code. Sessions log off automatically after a period of inactivity.

  • A tamper-evident audit log

    The activity log records field-level changes (before and after), access to client records and documents, prints and exports, sign-ins and sign-outs, and two-step setup. It is append-only and hash-chained, kept for seven years and then archived. Administrators see everyone’s activity; other users see their own.

  • Client portal access

    Clients enter the portal through an expiring secure link and a date-of-birth check, and every payment action needs a one-time code sent by email. Portal sessions log off after 15 minutes of inactivity.

  • Careful exports

    Data exports arrive as PDFs in one ZIP file that can be password-protected, and the download expires after 48 hours. Psychotherapy notes are left out unless you include them, with a HIPAA authorization warning.

  • Card payments through Stripe

    With the Client Payments add-on, card payments are processed by Stripe through your practice’s own Stripe account.

Your Business Associate Agreement.

EzPraxis offers a standard Business Associate Agreement (BAA), which a practice accepts when it registers or signs in. It is published in the app and linked from every system email. Its terms include:

  • Notice of a breach to your practice within 72 hours, or within 48 hours for psychotherapy notes, substance use disorder records, or a breach affecting 500 or more people.
  • After the service ends, 30 days to export your data, then destruction to NIST 800-88 with a certificate.
Read the BAA

For your compliance reviewer.

A summary to start your review. For anything not listed here, write to us. sales@ezpraxis.com

AreaWhat EzPraxis does
HostingAmazon Web Services, United States
Data separationAn isolated database for each new practice
Encryption in transitHTTPS with HSTS
Staff sign-inAmazon Cognito, with two-step verification by authenticator app or emailed code
Access controlRole-based: 8 built-in roles, about 95 permissions, assigned by location
Audit logAppend-only, hash-chained; kept 7 years, then archived
Automatic logoffStaff sessions and client portal sessions (15 minutes)
Client portalExpiring secure link, date-of-birth check, one-time code before payments
ExportsPDFs in a ZIP, optionally password-protected; the link expires after 48 hours
BAAStandard agreement, accepted at registration or sign-in
Breach notice (per the BAA)72 hours; 48 hours for psychotherapy notes, SUD records or 500+ people

Security questions.

Is EzPraxis HIPAA compliant?

There is no official HIPAA certification for software, and compliance also depends on how a practice works. EzPraxis gives you the safeguards: a Business Associate Agreement (BAA), hosting on AWS in the U.S., encryption in transit, role-based access, two-step verification for staff and a tamper-evident audit log.

Does EzPraxis offer a BAA?

Yes. The EzPraxis Business Associate Agreement is a standard agreement that a practice accepts when it registers or signs in, and you can read it in the app.

Where is our data stored?

In the United States, on Amazon Web Services.

Is our data separated from other practices?

Each new practice gets its own isolated database.

Can staff use two-step verification?

Yes, with an authenticator app or a code sent by email.

Does EzPraxis log who viewed a client’s record?

Yes. The activity log records access to client records and documents, as well as changes, prints, exports and sign-ins.

See EzPraxis with your own workflow.

Request a demo, and our team will walk you through scheduling, documentation and billing in EzPraxis.