HIPAA-oriented controls
PHI field protections, PHI view/write audit logging, burst detection, and governance designed for regulated healthcare billing data.
Security & compliance
Procurement teams evaluate ObsidianRCM on trust, not features alone. This overview covers our HIPAA-oriented posture — detailed documentation available during sales evaluation.
PHI field protections, PHI view/write audit logging, burst detection, and governance designed for regulated healthcare billing data.
TLS in transit; PHI encryption controls in the application layer. Production deployment aligned with healthcare security standards.
Granular permissions for billers, coders, finance, auditors, and administrators — scoped to practice and role.
Immutable activity history, practice audit log, compliance audit summary, login security events, and sessions activity reports.
Cloud-native multi-tenant architecture with Postgres row-level security (RLS) — tenant isolation at the database layer.
Audit log exports, compliance summary reports, and session activity for revenue integrity and IT governance.
SAML SSO and SCIM provisioning for enterprise IdP integration.
Server-side session binding, configurable idle timeout (practice/enterprise policy), secure cookie handling.
Operator elevated PHI access requires ticket + reason — fully audited. Support without end-user impersonation.
Procurement: BAA, security questionnaires, and architecture documentation provided during enterprise evaluation. This page is a marketing overview — not a legal attestation.
Onboarding checklist and operational readiness before live billing.
Test/production certification before 837 transmit.
Electronic claims blocked until practice is active and enrolled.
Request a demo and ask for our security documentation pack.