What buyers check first
Do you sign a business associate agreement?
Can software be certified for HIPAA?
What about your infrastructure provider?
Can we see what a staff member accessed?
HIPAA safeguards and the control behind each one
- Roadmap · M6
Business associate agreement
Onboarding will not treat a practice as live for patient data until the agreement step is complete. Electronic signature and countersigned PDF are not built yet — the agreement is still exchanged with us directly.
- Included
Encryption in transit and at rest
Transport security enforced on every connection by a two-year HSTS policy; data encrypted at rest by the platform. No patient data appears in any URL — record addresses carry an opaque identifier and nothing else.
- Included
Role-based access, enforced in the database
Access rules live in database row-level policies rather than in screen logic, so a permission cannot be bypassed by calling the API directly. Technicians see their own assigned clients only, and read back only the notes they wrote.
- Included
Audit log
Append-only, hash-chained per practice, written by a database trigger rather than by application code, so it cannot be skipped. Reads are events in their own right: opening a chart, opening a note and pulling billing history each write a row.
- Included
Multi-factor authentication for staff
Time-based one-time codes, enrolled per staff account from Settings. Offboarding takes effect on the departing user's next request rather than their next sign-in: the token already in their browser stops resolving to your practice immediately. Signed-in devices also sign out after an idle period the practice sets.
- Included
Patient right-of-access export
A full per-patient record export, as JSON for another system to ingest and as a readable HTML document for the family, with the request written to the audit log — so responding to a records request inside the required window is one action.
Case management, client management, patient management
Buyers searching for this substitute those three terms for “practice management” more or less freely, and the substitution is not sloppiness — it reflects what the organization calls the person it serves. A behavioral health agency has clients, a paediatric clinic has patients, a school-based or state-programme provider has cases.
The compliance question underneath is identical in all three, and it is worth stating plainly: HIPAA obligations follow the protected health information, not the vocabulary. If a system stores identifiable health information on behalf of a covered entity, the vendor is a business associate, must sign an agreement, and must implement the safeguards above. Whether its screens say “client” or “patient” changes nothing about that.
What the terms do signal is scope, and there the answer differs. This is practice management software: scheduling, intake, clinical documentation, charge capture and billing for a healthcare practice. It is not general-purpose case management for a social services agency, and it is not a CRM with a compliance wrapper — see the healthcare CRM page for where that boundary sits.
A practice that needs the first will find the vocabulary adapts. An organization that needs the second should evaluate something else, and it is cheaper to establish that now than after a trial.
What we do not claim
We do not hold ONC health IT certification. Physician practices billing Medicare may need a certified system for certain programs, while behavior-analytic and cash-pay practices generally do not. If certification is a requirement in your setting, MegAligna is not the right system, and that is worth establishing before a trial rather than during one.
Compliance controls you can open and check
Each safeguard above corresponds to a screen the practice owner can open rather than a statement to be taken on trust. The product exposes the audit log, per-user access and multi-factor status, a quarterly access-review flow, workforce training records and one-click offboarding as ordinary parts of the interface.
That matters at audit time: a HIPAA risk assessment asks what you implemented and how you know it works, and both answers come from screens you can print.
The controls behind these claims are itemised on the security and data commitments page, and the surfaces patients themselves touch are covered in the patient portal and intake.
Review the compliance controls in a trial
14 days, no card required. Use made-up patients while you evaluate — real patient information waits until a business associate agreement is in place.