Practice Better Trust Center
Our commitment to data privacy and security is embedded in everything we do.
See section
Compliance
HIPAA
CASA Tier 2
PIPEDA
GDPR
Monitoring
Continuously monitored by Secureframe
Subprocessors
Amazon Web Services
Box Inc.
Carry Technologies Inc.
dbt Labs
Deepgram
Documo
Datadog
Google Cloud
HubSpot
FAQs
Is my data stored and transmitted securely in Practice Better?
Your data is encrypted both in transit (between the browser and our servers) and also at rest (when stored on our servers).
We use AES-256 bit encryption while transferring your data to/from our servers.
We encrypt and store data on our servers using the AES 256-bit encryption.
AES-256 is the industry standard for storing and transferring sensitive data. All backups of your data are also encrypted using AES-256 bit encryption.
We use TLS 1.2 to encrypt your data both between your browser and our servers and between our servers and other internal networks.
Is any of my data stored or processed using cloud-based services?
Yes, we use Amazon Web Services (AWS) and Box.com to store your data in the cloud.
What third-party service providers does Practice Better use to store my data?
We use Amazon Web Services and Box.com to store your data in the cloud. Our core infrastructure is hosted using these two services. We have Business Associate Agreements (HIPAA BAA) and Data Processing Agreements which requires these providers to meet the highest level of security and privacy for storing personal health information.
What data is stored using these providers?
Any documents you upload to Practice Better will be stored in AWS. Any generated PDFs for completed forms, archived notes and protocols will also be stored here.
We use Box.com to facilitate our "Document Preview" feature within the portal. This allows PDFs, Word Docs and other document types to be viewed directly from the website without having to install 3rd party extensions or download files to your computer.
Do you have agreements with these third-party cloud providers?
We have HIPAA Business Associate Agreements and GDPR Data Processing Agreements with vendors which store and process data on our behalf.
How is my data protected from unauthorized access?
We have access controls, role-based authorization and IP whitelisting in place to restrict unauthorized access to cloud data.
Both AWS and Box.com adhere to strict SSAE 18 auditing and reporting standards for managing access to data stored in their systems.
Do these cloud service providers have the ability to permanently delete my data?
Yes, these providers are mandated to provide options (which we utilize) to completely wipe data from their servers.
What happens to my data in the event of a natural disaster?
Data is replicated across multiple redundant servers within our environment which mitigates the risk of loss of connectivity with one or more nodes (this guidance is specific to our AWS infrastructure - database and file servers).
How will I be notified of changes in third-party providers who will have access to my data?
Third parties services are outlined in our Privacy Policy. Updates to this list of providers are generally communicated via this Policy.
Can I export my clients' data?
You can export client data by following the instructions here:
https://help.practicebetter.io/hc/en-us/articles/234807887-Exporting-client-records
Your export will be provided as a Zip archive which includes spreadsheets of data included in the client file and documents associated with your client.
Data you or your clients have created/uploaded to PB will be wiped completed from our system after 30 days either via automated batch processes or data retention rules defined in our infrastructure. For example, we have policies defined to limit database backups to a maximum of 30 rolling days.
we run a nightly batch process to purge accounts (and related data) which have been marked for deletion by practitioner or client.