Sign In

Security & Compliance

AttendMD is built to operate securely inside HIPAA-regulated healthcare environments, with the access controls, encryption, and audit trails your compliance program requires.

Important: This page describes the security controls implemented in AttendMD. We do not claim SOC 2, HITRUST, or other certifications that have not been formally obtained. We do not use the phrase "HIPAA certified" — HIPAA does not provide an official certification program.

Your EMR
Clinical & census
Your RCM
Billing & claims
Your Call Tracking
Calls & leads
Your Marketing
Ads & analytics
AttendMD
Unify · Match · Analyze
Read-only · Encrypted
Live Dashboards
One operational view
AI Insights
Gaps surfaced early
Executive Reports
Board-ready summaries

Where applicable, AttendMD connects through read-only integrations.

Implemented security controls

These are the safeguards that are live in AttendMD today.

Role-Based Access Controls

Every user in AttendMD has a defined role. Access to facilities, data, and features is scoped precisely to what each role requires — nothing more.

Implemented

Multi-Factor Authentication

MFA is supported and can be required across your organization. Administrative roles can enforce MFA at the organization level.

Implemented

Audit Logging

Comprehensive audit logs capture user activity, data access, and administrative changes. Logs are retained and accessible to authorized administrators.

Implemented

Encryption In Transit and At Rest

All data transmitted to and from AttendMD is encrypted using TLS. Data at rest is encrypted using industry-standard algorithms.

Implemented

Read-Only Data Connections

Where applicable, AttendMD connects to external systems through read-only integrations. We don't write to your clinical or billing systems.

Implemented

Business Associate Agreements

AttendMD can enter into Business Associate Agreements (BAAs) when applicable for organizations operating in HIPAA-regulated environments.

Available

Business Associate Agreements

For organizations operating in HIPAA-regulated environments, AttendMD can enter into a Business Associate Agreement (BAA) when applicable. Contact us to request a BAA as part of your onboarding.

We also support detailed security review processes for organizations with specific compliance requirements.

BAA available upon request
Supports HIPAA-regulated environments
Detailed security review process available
Contact us for compliance-specific requirements

Security & Compliance FAQ

Yes — AttendMD is built for HIPAA-regulated environments from the ground up. The platform runs on infrastructure that is independently audited against SOC 2 and supports HIPAA workloads, we hold Business Associate Agreements with our infrastructure partners, and we execute BAAs with our customers. For substance use disorder treatment providers, we also support Qualified Service Organization Agreements (QSOAs) under 42 CFR Part 2. The technical safeguards HIPAA expects of a business associate — encryption in transit and at rest, role-based access, MFA, and comprehensive audit logging — are implemented and enforced in the platform today. (HIPAA has no official certification program, so no vendor can truthfully claim to be "HIPAA certified" — what matters is the controls, and ours are live.)

AttendMD processes the operational, billing, and marketing performance data your organization connects — attendance, scheduling, census, billing, related client records, and advertising analytics from direct OAuth connections to Google Ads and Google Analytics. Where that data includes protected health information (PHI), we process it as a business associate under a Business Associate Agreement, limited to what the service requires. AttendMD is not an EHR and does not replace your clinical record system.

Defense in depth, enforced at the deepest layer we control. Access control runs at the database layer on every single query — not just in the application — so a user can only ever reach the facilities and data their role was explicitly granted, even if a bug slipped through the application in front of it. Multi-factor authentication protects accounts, access to protected records is written to tamper-evident audit logs, and all data is encrypted in transit and at rest on SOC 2-audited, HIPAA-eligible infrastructure. The platform is engineered to fail closed: when anything unexpected happens, the default is to deny access, not allow it. And before any change ships, it must pass an automated adversarial security suite — real attack scenarios run against the platform on every release. Bring your compliance team's hardest questions to the demo; we welcome the review.

Our infrastructure is SOC 2-audited; the platform itself is not yet certified — and we won't blur that line. AttendMD runs entirely on SOC 2-audited, HIPAA-eligible infrastructure, and the platform is engineered to those same standards throughout: least-privilege access enforced at the database layer, MFA, tamper-evident audit logging, and encryption in transit and at rest. We follow a simple rule that protects every claim on this page: we display only credentials we have formally earned, and platform-level certification is planned as we scale. In the meantime we back our security with something a badge alone can't give you — open review. Request our security documentation and bring your compliance team's hardest questions; the architecture holds up.

No. Where applicable, AttendMD uses read-only connections to external systems. We surface and organize operational data — we do not modify records in your source systems.

Users are assigned to specific facilities within their organization. Owners have organization-wide access. Every other role is explicitly assigned to the facilities they need — no implicit cross-facility access.

Have a specific security or compliance question?

Contact us to discuss your organization's compliance requirements.