Identity & Access
Individual accounts, role checks, secure sessions, facility scoping, and login protections.
Individual accounts, role checks, secure sessions, facility scoping, and login protections.
Clinical content remains inside authenticated workflows rather than ordinary SMS messages.
Security-relevant activity and clinical workflow events can be recorded for review.
Production use should be restricted to HTTPS with protected secrets and secure hosting.
How SBARAlerts collects, uses, protects, retains, and discloses information.
Review documentRules governing access, accounts, clinical responsibility, fees, and platform use.
Review documentSafeguards, Business Associate responsibilities, and customer obligations.
Review documentApplication controls, encryption, logging, access management, and continuity.
Review documentKey provisions addressed in a customer-specific Business Associate Agreement.
Review documentSecurity-event triage, containment, assessment, notification, and recovery.
Review documentRetention, backup rotation, service termination, deletion, and destruction.
Review documentVendor categories supporting hosting, SMS, email, backups, and operations.
Review documentPermitted healthcare use and prohibited conduct designed to protect the platform.
Review documentEssential cookies, secure sessions, analytics considerations, and browser controls.
Review documentAccessibility commitment, standards, known limitations, and feedback process.
Review documentHuman-review and clinical-safety limits for AI-assisted features.
Review documentOverview of availability, support, maintenance, backups, and service credits.
Review documentSupplemental California privacy disclosures and request rights.
Review documentIntellectual-property ownership and infringement-reporting procedures.
Review document