vPro EMR

Getting your facility ready…

vProEMR
Trust & Security

Security at vPro EMR

vPro EMR is the authoritative clinical record for behavioral-health and addiction-treatment facilities. Protecting that data, and proving we do, is foundational, not an afterthought.

23 security controls continuously monitoredLast verified Sep 29, 2026

Our security program

  • Encryption in transit (TLS 1.2+) and at rest (AES-256), with application-layer field encryption for the most sensitive data.
  • Per-tenant data isolation enforced at the database by row-level security, every table, deny-by-default.
  • Least-privilege access with multi-factor authentication required on privileged accounts, and a unique identity per user.
  • An append-only audit trail of PHI access, retained six years, with automated anomaly review.
  • Continuous, automated control monitoring, the security posture is re-verified daily, not once a year.
  • HIPAA Business Associate Agreements available; substance-use-disorder records handled under 42 CFR Part 2.

Frameworks we map to

Every control is mapped to the frameworks our customers and their auditors report against.

SOC 2HIPAA Security RuleHITRUST CSF42 CFR Part 2

How we prove it

Continuous evidence, not an annual snapshot.

An in-house engine checks every control automatically each day and records the result, so the posture we show is current, not a point-in-time report.

A tamper-evident record.

The compliance log is append-only and hash-chained, so past evidence cannot be quietly altered after the fact.

Findings tracked to closure.

A gap opens a tracked remediation item, and the engine re-verifies its own integrity every day.

How we handle your data

What trusting an EMR really means

An EMR holds the most sensitive record a person has, in a field where a disclosure can cost someone their job, their custody, or their recovery. Trust is not a badge on a page. It is saying plainly what we do with that data, and being built so we cannot quietly do otherwise.

How we handle PII and PHI

The facility is the covered entity; we operate as its Business Associate under a signed BAA, and substance-use-disorder records are handled under 42 CFR Part 2. PHI is encrypted in transit and at rest, the most sensitive fields carry an extra layer of application-level encryption, and every view, edit, and disclosure lands in an append-only audit trail.

How we keep it that way

Access is least-privilege and tenant-isolated at the database itself, multi-factor authentication is required on privileged accounts, and an in-house engine re-verifies our controls every day and tracks findings to closure.

What we collect

Only what a clinical record requires and the facility enters: demographics, insurance and authorization detail, clinical documentation, medications, labs, and the audit metadata that proves who did what and when.

What we don't collect

We don't buy or enrich patient data from third parties, we don't run advertising or third-party tracking pixels inside the clinical application, and we don't use PHI to train AI models.

What's stored, and what isn't

The record and its full version history live in a HIPAA-covered, per-facility-isolated database; nothing clinical is ever hard-deleted, because a legal record can't be. We don't put PHI into third-party analytics, and the marketing site you're on now collects no PHI at all.