Kotis takes the security of patient and clinic data seriously across every scheduling, telehealth, and documentation system we deploy. Our practices are designed to support HIPAA compliance for clinic clients.
Our Approach
- Encryption: Data is encrypted in transit via TLS and at rest using industry-standard encryption.
- Access control: Role-based permissions ensure a front-desk staff member, provider, or biller can only view records their role is authorized to access.
- Minimum necessary access: Patient records are scoped to the care team directly involved in that patient's treatment.
- Audit logging: All access to protected health information is logged and available for compliance review.
Payment Security
Kotis does not store credit card numbers on our own servers. All payment processing is handled through PCI-DSS Level 1 certified providers.
Vulnerability Reporting
If you believe you've found a security vulnerability in our systems or in a platform we've deployed for a client, please email security@kotisenterprises.us. We respond to all reports within 48 hours.