Features

Everything your practice needs to stay compliant

Six compliance modules, three AI tools, and enterprise security. All in one platform. No extra software to buy.

Compliance Modules

Six modules covering every HIPAA requirement

Core Compliance

Risk Assessments

Guided, ONC SRA-aligned questionnaires walk your team through every Security Rule requirement, one step at a time. Finish your assessment and the AI generates a plain-English summary your leadership can actually use.

25+ weighted questions across all safeguard categories
Automatic risk scoring with section breakdown
Gap report with regulation references
One-click remediation task generation
AI Executive Summary for leadership (on completion)
PDF report export for audits

Core Compliance Module

Policy Management

Policy Library & AI Generator

Choose from 20+ pre-built templates or let the AI write a custom policy based on your practice profile. Either way, you get version control and electronic signatures.

20+ professionally written policy templates
AI-powered custom policy generation
Version control with full change history
Electronic signature with IP/timestamp audit trail
Per-employee signature tracking
Organization-specific customization

Policy Management Module

Workforce Training

Training & Quiz Engine

Assign training to staff, track who's completed it, and test their knowledge with graded quizzes. Compliance training that actually leaves a paper trail.

Multi-section training courses
Graded quizzes with configurable passing scores
Automatic completion tracking
Answer review with explanations
Annual retraining reminders

Workforce Training Module

Vendor Management

BAA Tracker

Know exactly which vendors have access to patient data. Get alerts before agreements expire and keep copies of the actual BAA documents on file.

Vendor inventory with contact details
PHI access flagging
90-day expiration alerts
Document attachment for BAA copies
Status dashboard

Vendor Management Module

Incident Response

Incident Management & Breach Assessment

When something goes wrong, the platform walks you through the HIPAA 4-factor breach risk analysis. You'll know whether you need to report, and you'll have the documentation to show you handled it correctly.

Structured reporting with severity levels
HIPAA 4-factor breach risk assessment
Breach determination workflow
Notification deadline tracking
Root cause and corrective action documentation

Incident Response Module

Documentation

Document Vault & Task Tracker

One secure place to store everything an auditor might ask for. Policies, BAAs, risk reports. Plus task tracking to keep your remediation work moving.

Categorized document storage (PDF, Office, images)
25 MB max file size with type validation
Task creation with priorities and assignments
Overdue detection and filtering
Complete audit trail

Documentation Module

AI Tools

AI-powered compliance guidance

Three AI tools included in every plan. No extra cost. No configuration needed.

AI Compliance Assistant

Got a HIPAA question? Just ask. The AI assistant knows the Security Rule, Privacy Rule, and Breach Notification Rule inside and out. Any time of day.

Ask any HIPAA question in plain English
Answers cite specific rule sections
Conversation history saved per session
Starter questions to guide new users
Powered by enterprise-grade language models

AI Risk Assessment Summaries

Finished your risk assessment? The AI turns your scores into a plain-English report your leadership can actually read and act on. Available once you complete an assessment.

5-section narrative report in plain English
Prioritized findings with HIPAA references
Critical gaps and remediation recommendations
Positive findings to show what's working
One-click copy for board or leadership packets

AI Policy Generator

Tell the AI about your practice and it writes your policies for you. Your EHR, your locations, your setup. Done in seconds.

10 policy types supported
Uses your practice profile (EHR, size, locations)
Generates full policy text, not just an outline
Editable before assignment to staff
Review and customize before publishing

AI features are powered by enterprise-grade language models. AI provides guidance, not legal advice. Your data stays in your account.

Team Management

Built for teams of any size

Whether it's just you managing compliance or a team spread across multiple locations, you won't outgrow the platform.

Role-Based User Management

Two distinct roles keep things clean. Admins run the compliance program; employees complete training and sign policies. Employees are always free, no per-user fees ever.

Invite users via email
Assign admin or employee role
Deactivate accounts instantly
Compliance tracking per user

CSV Bulk Import

Onboard your entire staff at once. Upload a CSV with names, emails, and roles. The platform shows you a preview before making any changes.

Upload CSV with name, email, role
Preview screen shows ready/duplicate/error
Confirm before any accounts are created
Download sample template
Roles normalized automatically
Enterprise

SSO / SAML Authentication

Enterprise customers can integrate with Azure AD, Okta, or any SAML 2.0 identity provider. Staff sign in with their existing credentials. No new passwords to manage.

Azure AD & Okta supported
SAML 2.0 compatible
Auto-provision new users on first login
Per-organization configuration
IT team configures once

Security

Security controls built for HIPAA

We hold our own platform to the same standards we help you achieve.

Mandatory Two-Factor Authentication

MFA is required for every user, no exceptions. Supports TOTP authenticator apps (Google Authenticator, Authy) and email-based verification codes. Backup codes available for account recovery.

Email Verification

All new accounts must verify their email address before accessing the platform. Invited users are automatically verified through their invitation link.

Role-Based Access Control

Admins manage the compliance program; employees see only what they need. Cross-organization data access is blocked at the database level.

Encrypted Storage

All data encrypted at rest and in transit. Compliance data is stored on hardened infrastructure and never commingled between organizations.

Complete Audit Trails

Every login, document access, policy signature, and configuration change is logged with user, timestamp, and IP address. If OCR ever comes knocking, the paper trail is ready.

Ready to see it in action?