Security & Compliance

Enterprise-grade security with HIPAA compliance, comprehensive audit logging, and advanced access controls to protect patient data.

  • AES-256 encryption at rest and TLS 1.3 in transit
  • MFA with TOTP apps, SMS codes and hardware security keys
  • An audit trail of all system access and PHI interactions

HIPAA Compliance

Built around the requirements of HIPAA, HITECH, and the Australian Privacy Principles.

Data Encryption

AES-256 encryption at rest and TLS 1.3 in transit. All PHI is encrypted with tenant-specific keys managed in hardware security modules.

Multi-Factor Authentication

Enforce MFA for all users or specific roles. Support for TOTP apps, SMS codes, and hardware security keys.

Comprehensive Audit Logs

Tamper-proof audit trail of all system access and PHI interactions. Advanced search, export, and retention policies.

Role-Based Access

Granular permission system with predefined roles and custom configurations. Principle of least privilege enforced throughout.

Session Management

Configurable session timeouts, concurrent session limits, and forced logout. View and terminate active sessions remotely.

Threat Detection

Real-time monitoring for suspicious activity. Failed login tracking, IP blacklisting, and automated account lockout.

Data Residency

Choose where your data is stored. Regional deployments in Australia, New Zealand, and South America ensure local data sovereignty.

See Security & Compliance on a live walkthrough

Book a walkthrough and see how Clarirad fits your practice's workflow, from booking to billing.