Getting your facility ready…
Behavioral-health data carries some of the strictest confidentiality rules in healthcare. vPro EMR is built so the record protects itself and verifies itself.
We sign a Business Associate Agreement (BAA) with every client. Access is least-privilege and scoped per facility and location; PHI is protected in transit and at rest.
Part 2 confidentiality for substance-use records is a data invariant in the model, not a checkbox. Consent and redisclosure rules are enforced structurally.
The platform is aligned with the SOC 2 Trust Services Criteria and runs a continuous-evidence engine that collects control evidence on an ongoing basis.
E-prescribing certification is in progress. Prescriptions route through DoseSpot to the national pharmacy network; the prescriber chooses the medication and the patient chooses the pharmacy.
Every create, edit, and signature is captured in an append-only trail with before/after detail. Signed = immutable, so a lost note or a broken signature is structurally impossible.
Multi-facility and multi-location from a single identity, with per-location scoping enforced server-side: one portfolio, cleanly separated data.
Our continuous-evidence engine powers a live Trust Center where you can review our compliance posture and subprocessors.
vPro EMR is described as HIPAA compliant and SOC 2 Type II–aligned. We do not represent the product as “SOC 2 certified,” “HITRUST certified,” or “HIPAA certified.”