Most vendor compliance pages are a wall of logos. This one names the credential, states its current status, and separates what the software does from what remains your organization's obligation. If a line here matters to your contract, ask us for the underlying document — we will send it.
A certification is issued for a specific product version by a specific body, for a specific period. We list ours that way, because that is the only way the statement is useful to your compliance officer.
Certification is granted per product version against named criteria and listed publicly on the CHPL. Ask us for the certificate and CHPL identifier that applies to the version and contract term you are buying — and put it in the agreement.
Access control, unique user identification, automatic logoff, encryption in transit and at rest, immutable audit controls, integrity controls and transmission security. A Business Associate Agreement is executed before any PHI is loaded.
Security, Availability and Confidentiality criteria over an observation window. The report is shared under NDA. Ask for the observation period, the scope and any exceptions noted — a report with no exceptions and a two-month window is not the same as a clean twelve-month one.
Frequently required by health systems and larger payers as a condition of vendor onboarding. On the roadmap; not held today. If your procurement process requires it, tell us during evaluation so we can talk about timing honestly.
Electronic prescribing of controlled substances requires an independent audit or certification of the application before it can be used for Schedule II–V prescribing. Confirm the current certification and its date before enabling EPCS for your providers.
Network certification for new prescriptions, renewals, medication history, formulary and benefit, and real-time prescription benefit. Required to route prescriptions to retail and mail-order pharmacies.
Patient-facing surfaces are built to WCAG 2.1 AA. A VPAT can be provided for procurement. Federally funded organizations frequently need this in writing — ask early rather than at contract signature.
Query-based exchange with other organizations through a national framework. On the roadmap. Today, exchange runs through direct FHIR R4 APIs, C-CDA document exchange and Direct secure messaging.
Clovai never stores primary account numbers. Card entry is tokenized by the payment processor, which reduces your PCI scope. Your merchant agreement and your own PCI obligations remain yours.
Grouped the way a compliance officer thinks about it, not the way a feature list is organized.
Role-based access scoped to the minimum necessary, patient access and amendment requests tracked to the statutory deadline, accounting of disclosures, and restriction requests recorded against the record.
Unique user identification, MFA, automatic logoff, emergency access procedure, immutable audit controls, integrity verification and encryption in transit and at rest.
Access-log analytics to identify impermissible access, plus the reporting needed to meet the 60-day individual notification and annual HHS reporting obligations.
Segmented consent and disclosure controls for SUD treatment records, which carry stricter re-disclosure rules than general PHI.
Configurable consent capture and data-subject request handling for states with additional requirements beyond HIPAA.
Configurable proxy access rules so a parent portal account does not expose services a minor consented to independently under state law.
Electronic health information is made available without special effort, delay or fee. Access, exchange and use are not conditioned on staying a customer.
Data captured and exposed in the standardized classes and elements that define the U.S. Core Data for Interoperability.
Standards-based single-patient and multi-patient API access, including for third-party apps the patient authorizes.
Consolidated CDA generation and consumption, plus Direct secure messaging for referrals and transitions of care.
Electronic lab reporting, electronic case reporting, immunization registry submission and syndromic surveillance where your jurisdiction requires it.
A complete, structured export of your organization's data on demand, at any time, at no charge — written into the agreement rather than promised on a page.
Identity proofing, two-factor authentication, logical access controls and the auditable record DEA requires for electronic controlled-substance prescribing.
PDMP query at the point of prescribing, with the check recorded in the encounter — many states mandate the query and the documentation of it.
In-office test ordering and resulting with the CLIA certificate number carried onto the claim, plus QC documentation for the tests you perform.
Fired at order entry rather than after signature, with override reasons captured — the override record is what an audit asks for.
Place of service 02/10 and modifiers applied automatically; provider licensure tracked by state with warnings when a scheduled visit falls outside an active license.
Closed-loop acknowledgment so an abnormal result cannot sit unreviewed — one of the most common sources of ambulatory malpractice exposure.
270/271, 276/277, 278, 834, 837P/837I and 835 in the mandated formats and versions.
Procedure-to-procedure and medically-unlikely edits applied before submission, with the modifier logic that determines whether a bypass is legitimate.
Local and national coverage determinations checked against the diagnosis and procedure combination before the claim leaves.
Generated within statutory timelines for self-pay and uninsured patients, with delivery tracked and retained as evidence.
Charges derived from the signed documentation, level-of-service support surfaced at coding, and an audit trail linking every claim line to what was documented and by whom.
Quality, Promoting Interoperability and Improvement Activities measures computed continuously with numerator and denominator detail.
T3 capture, matching and six-year retention, saleable-return verification, and a documented suspect/illegitimate product workflow.
Perpetual inventory by NDC, witnessed waste with reason codes, biennial inventory support and Form 222 / CSOS electronic ordering.
Encounter-level eligibility, NDC accumulation, split billing, replenishment tracking and duplicate-discount prevention with a HRSA-audit-shaped trail.
Documentation support for compounding logs and hazardous drug handling where your operation performs them.
Lot-to-patient traceability so a recall is answered by naming affected patients rather than estimating a date range.
Continuous temperature monitoring with excursion alerts and retained logs — what a surveyor asks to see, produced as a report.
Monthly screening of employees, contracted providers and vendors against the LEIE and SAM, with the search evidence retained — federal guidance expects monthly, and the penalty runs per claim.
Licenses, DEA registrations, board certification, malpractice coverage and CAQH attestations tracked to expiration with documented verification.
Status by provider, NPI and payer, including effective dates — so services are not rendered under a provider who is not yet enrolled.
Bloodborne pathogens, hazard communication and workplace violence prevention training assigned by role with signed attestations.
Overtime calculated on actual worked hours, exempt/non-exempt classification tracking, and ACA applicable-large-employer and 1095-C reporting computed year-round.
Policy acknowledgment, training records, reporting mechanism logs and corrective action documentation — the artifacts an effective compliance program has to be able to produce.
Written the way your compliance committee would write it: the question being asked, where the loss actually occurs, the controls, and the evidence you would produce if someone asked you to prove it.
Denials that are never reworked, claims that pass a payer's timely-filing limit, services rendered without a required prior authorization, payments below the contracted rate absorbed as "contractual adjustment," and patient balances that age past collectability. Most of this is invisible until it is written off — the loss looks like a rounding line rather than a failure.
Clean claim rate, first-pass yield, denial rate by root cause, net collection rate, A/R aging by payer, and underpayment variance — all reportable by period, provider and site.
False Claims Act liability for services that documentation does not support, RAC/TPE/UPIC audits and the extrapolated repayments that follow, level-of-service and medical-necessity challenges, and Stark and Anti-Kickback exposure in referral and compensation arrangements. The costly part is rarely the individual claim — it is the extrapolation across a sample.
A complete encounter package — note, orders, results, coding rationale, authorization, and the full revision history with attribution — produced as an export rather than reconstructed by hand.
Ransomware with clinical downtime, impermissible access by insiders, breach notification duties within 60 days, OCR enforcement and state attorney general actions, and third-party compromise through a vendor with access to your environment. Healthcare remains among the most targeted sectors, and ambulatory organizations are targeted precisely because they are assumed to be less defended.
Access logs per user and per record, the security assessment and penetration test summaries, restore test records, and the executed BAA with its subcontractor schedule.
Medication errors and missed interactions or allergies, abnormal results that nobody acknowledges, referrals that never close, care gaps in chronic and preventive management, and documentation that will not withstand review if the case becomes a claim. Failure to follow up on an abnormal result is one of the most common ambulatory malpractice allegations.
Results acknowledgment turnaround, unclosed referral aging, care-gap closure rates, and override reason reporting by provider.
An expired state license, a lapsed DEA registration, a missed payer revalidation, or an employed or contracted individual on the OIG exclusion list. Any one of these makes already-rendered services retroactively unbillable — and in the exclusion case, exposes the organization to civil monetary penalties on every claim the excluded person touched, plus repayment.
The credentialing file per provider, the monthly screening log with retained results, and an enrollment status report by NPI and payer.
Information-blocking exposure when patients or their apps cannot get electronic health information, referral partners who cannot receive records, and the renewal conversation where the cost of leaving is deliberately higher than the cost of staying. Lock-in is not an accident of architecture; in this market it is frequently a commercial strategy.
API access logs, export records, and the data-portability clause in your service agreement — the one you should read before you sign, not after.
Ransomware against a practice is not an IT incident — it is a clinical safety event, a HIPAA breach and a revenue interruption at the same time. These are the controls behind the platform.
Every customer runs in a logically isolated tenant with its own data boundary. There is no shared table where one organization's query could reach another's records.
TLS 1.2+ in transit and AES-256 at rest, including backups. Key management is separated from application access.
Unique named accounts, MFA, role-based least privilege scoped by module, action and site, automatic session timeout, and SSO/SAML on the higher tiers.
Immutable, tamper-evident logs of every read and write to PHI, retained and searchable — this is both a HIPAA requirement and your first tool in a breach investigation.
Automated backups with geographic redundancy and periodically tested restores. A backup that has never been restored is a hypothesis, not a control.
Dependency scanning, patch management on a defined cadence, and periodic third-party penetration testing with findings tracked to closure.
Subcontractors that touch PHI are under BAAs, assessed before onboarding and reviewed periodically. Your BAA names them.
Documented read-only access and downtime workflows, because "the system is unavailable" cannot mean "the clinic stops seeing patients."
PHI stays inside your tenant and never trains models shared across customers. AI-assisted actions require human approval and are fully attributed in the audit log.
The Cures Act made information blocking unlawful. It did not make every vendor cooperative. These commitments are in the service agreement, not just on this page.
A full structured export of your clinical, financial and operational data on demand — whether you are staying or leaving. No exit fee, no "data extraction project," no per-record charge.
FHIR R4 single- and multi-patient access to USCDI data, available to your patients and the third-party applications they authorize, without special effort or delay.
We do not condition access, exchange or use of electronic health information on remaining a customer, and we do not charge fees that would constitute information blocking.
C-CDA generation and consumption plus Direct secure messaging, so transitions of care actually carry the record with them.
Documented, versioned APIs with deprecation notice periods. If we change something you built on, you find out with time to react, not in a release note after the fact.
Availability commitments defined in the agreement with a status page and incident history — including the incidents that did not go well.
The measure of a platform is not whether it has an incident. It is what your practice can still do while one is happening, and how quickly you learn about it.
Monitoring with defined severity levels and escalation paths. Security incidents that may involve PHI trigger the notification process defined in your BAA.
Communication within the timeframes your BAA specifies, with the information you need to meet your own 60-day individual notification obligation — not a summary weeks later.
Read-only access and documented downtime workflows so patients can still be seen and documentation can be reconciled afterward.
Claims queue and submit once service is restored. Timely-filing exposure is tracked through the incident rather than discovered after it.
RTO and RPO defined in the agreement, with restores tested rather than assumed.
A written root cause and corrective action summary shared with affected customers. If it happened once and nothing changed, it will happen again.
Procurement, compliance and IT security teams should not have to take a website's word for it. Ask, and we will send these.
Request the compliance package →Seriously. The questions they ask are the ones worth answering, and we would rather answer them now than at implementation.