EHR security
EHR security and HIPAA: how EzPraxis protects your data.
The questions your compliance reviewer will ask, answered with the safeguards EzPraxis actually has: where data lives, who can see it, what gets logged, and the BAA.
HIPAA and EzPraxis.
There is no official HIPAA certification for software, and compliance depends on how a practice works, not only on the systems it uses. What a vendor can do is provide the safeguards and offer the Business Associate Agreement that HIPAA requires. This is what EzPraxis provides.
Hosted on AWS in the United States
The application runs on Amazon Web Services in the U.S.: Amazon ECS for the application, a SQL Server database, Amazon S3 for documents, Amazon Cognito for staff sign-in and Amazon SES for email. Each new practice gets its own isolated database.
Encrypted in transit
Every connection uses HTTPS, with HSTS so that browsers never fall back to an unencrypted connection.
Role-based access
Eight built-in roles and about 95 permissions, each scoped to a user’s own clients, their supervisees or the whole practice, and assigned by location. One person can hold several roles.
Two-step verification for staff
Staff can confirm their sign-in with an authenticator app or an emailed code. Sessions log off automatically after a period of inactivity.
A tamper-evident audit log
The activity log records field-level changes (before and after), access to client records and documents, prints and exports, sign-ins and sign-outs, and two-step setup. It is append-only and hash-chained, kept for seven years and then archived. Administrators see everyone’s activity; other users see their own.
Client portal access
Clients enter the portal through an expiring secure link and a date-of-birth check, and every payment action needs a one-time code sent by email. Portal sessions log off after 15 minutes of inactivity.
Careful exports
Data exports arrive as PDFs in one ZIP file that can be password-protected, and the download expires after 48 hours. Psychotherapy notes are left out unless you include them, with a HIPAA authorization warning.
Card payments through Stripe
With the Client Payments add-on, card payments are processed by Stripe through your practice’s own Stripe account.
Your Business Associate Agreement.
EzPraxis offers a standard Business Associate Agreement (BAA), which a practice accepts when it registers or signs in. It is published in the app and linked from every system email. Its terms include:
- Notice of a breach to your practice within 72 hours, or within 48 hours for psychotherapy notes, substance use disorder records, or a breach affecting 500 or more people.
- After the service ends, 30 days to export your data, then destruction to NIST 800-88 with a certificate.
For your compliance reviewer.
A summary to start your review. For anything not listed here, write to us. sales@ezpraxis.com
| Area | What EzPraxis does |
|---|---|
| Hosting | Amazon Web Services, United States |
| Data separation | An isolated database for each new practice |
| Encryption in transit | HTTPS with HSTS |
| Staff sign-in | Amazon Cognito, with two-step verification by authenticator app or emailed code |
| Access control | Role-based: 8 built-in roles, about 95 permissions, assigned by location |
| Audit log | Append-only, hash-chained; kept 7 years, then archived |
| Automatic logoff | Staff sessions and client portal sessions (15 minutes) |
| Client portal | Expiring secure link, date-of-birth check, one-time code before payments |
| Exports | PDFs in a ZIP, optionally password-protected; the link expires after 48 hours |
| BAA | Standard agreement, accepted at registration or sign-in |
| Breach notice (per the BAA) | 72 hours; 48 hours for psychotherapy notes, SUD records or 500+ people |
Security questions.
Is EzPraxis HIPAA compliant?
There is no official HIPAA certification for software, and compliance also depends on how a practice works. EzPraxis gives you the safeguards: a Business Associate Agreement (BAA), hosting on AWS in the U.S., encryption in transit, role-based access, two-step verification for staff and a tamper-evident audit log.
Does EzPraxis offer a BAA?
Yes. The EzPraxis Business Associate Agreement is a standard agreement that a practice accepts when it registers or signs in, and you can read it in the app.
Where is our data stored?
In the United States, on Amazon Web Services.
Is our data separated from other practices?
Each new practice gets its own isolated database.
Can staff use two-step verification?
Yes, with an authenticator app or a code sent by email.
Does EzPraxis log who viewed a client’s record?
Yes. The activity log records access to client records and documents, as well as changes, prints, exports and sign-ins.
See EzPraxis with your own workflow.
Request a demo, and our team will walk you through scheduling, documentation and billing in EzPraxis.