Security at vPro EMR
vPro EMR is the authoritative clinical record for behavioral-health and addiction-treatment facilities. Protecting that data, and proving we do, is foundational, not an afterthought.
Our security program
- Encryption in transit (TLS 1.2+) and at rest (AES-256), with application-layer field encryption for the most sensitive data.
- Per-tenant data isolation enforced at the database by row-level security, every table, deny-by-default.
- Least-privilege access with multi-factor authentication required on privileged accounts, and a unique identity per user.
- An append-only audit trail of PHI access, retained six years, with automated anomaly review.
- Continuous, automated control monitoring, the security posture is re-verified daily, not once a year.
- HIPAA Business Associate Agreements available; substance-use-disorder records handled under 42 CFR Part 2.
Frameworks we map to
Every control is mapped to the frameworks our customers and their auditors report against.
How we prove it
An in-house engine checks every control automatically each day and records the result, so the posture we show is current, not a point-in-time report.
The compliance log is append-only and hash-chained, so past evidence cannot be quietly altered after the fact.
A gap opens a tracked remediation item, and the engine re-verifies its own integrity every day.
What trusting an EMR really means
An EMR holds the most sensitive record a person has, in a field where a disclosure can cost someone their job, their custody, or their recovery. Trust is not a badge on a page. It is saying plainly what we do with that data, and being built so we cannot quietly do otherwise.
How we handle PII and PHI
The facility is the covered entity; we operate as its Business Associate under a signed BAA, and substance-use-disorder records are handled under 42 CFR Part 2. PHI is encrypted in transit and at rest, the most sensitive fields carry an extra layer of application-level encryption, and every view, edit, and disclosure lands in an append-only audit trail.
How we keep it that way
Access is least-privilege and tenant-isolated at the database itself, multi-factor authentication is required on privileged accounts, and an in-house engine re-verifies our controls every day and tracks findings to closure.
What we collect
Only what a clinical record requires and the facility enters: demographics, insurance and authorization detail, clinical documentation, medications, labs, and the audit metadata that proves who did what and when.
What we don't collect
We don't buy or enrich patient data from third parties, we don't run advertising or third-party tracking pixels inside the clinical application, and we don't use PHI to train AI models.
What's stored, and what isn't
The record and its full version history live in a HIPAA-covered, per-facility-isolated database; nothing clinical is ever hard-deleted, because a legal record can't be. We don't put PHI into third-party analytics, and the marketing site you're on now collects no PHI at all.