Coming June 2027. Not yet for sale.

Tell us what you need
PracticeCore

Your data. Your hardware. If you want it.

We treat your PHI like it is our own. And if you would rather it never leave your building, you can self-host the whole stack.

Every action, logged. Every role, scoped.

Users, roles, permissions, and the access log.

Staff accounts with roles and permission modules, and an access log of every event: who, what, when, from where, with severity and outcome. Searchable, filterable, auto-refreshing.
Users and groups: staff accounts, roles, permission modules, and the access log

Sign in the way security teams prefer.

Email-first sign-in with per-user MFA: authenticator codes or a hardware security key such as a YubiKey or a FIDO2 smart card, enforced at the organization level. SSO available for groups.
PracticeCore's sign-in screen

Security primitives you can audit.

  • HIPAA-aligned by default

    Designed to the HIPAA Security Rule; a BAA is part of every customer agreement at launch. Encryption at rest (AES-256) and in transit (TLS 1.3). Logged, signed, retained.

  • Role-based access and row-level security

    Access control on every endpoint. Database-level row isolation so a misconfigured query cannot cross tenants.

  • Full audit trail

    Every access, every change, every export, recorded with user, time, IP and prior value. Searchable.

  • Per-user MFA and security keys

    TOTP or hardware key, enforced at the organization level. SSO available for groups.

  • Encrypted backups

    Point-in-time recovery. Backups encrypted at rest with customer-managed keys for self-hosted deployments.

  • Self-host option

    The Docker Compose stack runs on your hardware. The patient record never leaves the building.

Your data, your export, your rules.

Every chart, every claim, every note is yours. Export at any time in open formats. No proprietary lock-in. No “we’ll get back to you in ninety days.” If you decide to leave, you leave with everything.

Want the security review packet?

Architecture diagrams, the SOC 2 roadmap, the BAA template, and the self-host runbook.