Security & HIPAA

We measure efficiency, not the patient chart.

Synchrony tracks how long each step of a surgical case takes and who owned it. No patient names, no medical record numbers, no diagnoses, no charts. Tracking how efficiently a room runs doesn’t require any of them, so we don’t collect them. It is a standalone platform with no connection to your EHR.

0

patient records stored

0

EHR integrations required

AWS

hosted on industry standard platform

BAA

signed with every customer

There is no patient data in Synchrony

A case in Synchrony is a start time, a set of intervals, the roles that owned them, and a room number. That is the whole record. Cases are identified by a short number like Case #4417, with no name attached to it. We are not an electronic medical record and we do not connect to one, so the information a chart holds never reaches us.

What Synchrony never stores

  • Patient names or medical record numbers
  • Diagnoses, clinical notes, or histories
  • Imaging, labs, or pathology
  • Billing or insurance information
  • Anything resembling a full patient chart

All Synchrony stores

  • Case flow intervals and their timestamps
  • Surgical staff names and their assigned roles
  • Schedule metadata: operating room, surgery type, date
  • A per-case identifier, not a patient chart
  • Delay reasons and performance metrics

Most HIPAA reviews come down to working out what a breach would expose. In our case it would expose no patient information at all.

We don’t connect to any systems you run

Synchrony is a standalone platform. It does not require any integration with your EHR or other clinical systems. There is no interface engine and no HL7 or FHIR feed to build, and we have no read access to your systems. Data enters in one place: the tablets in your operating rooms.

No integration to review

Your security team is evaluating one vendor. There is no connection into your clinical systems, so there is no interface to scope and no second review queue to sit in.

No IT project to schedule

You set up Synchrony by defining your own intervals, targets, and roles. Nothing has to be built or tested against another system first.

Nothing to unwind

Nothing was ever wired in, so stopping means switching off the tablets. There is no interface to decommission afterwards.

How we protect what we do hold

Staff names, schedules, and performance data still deserve protection. These are the controls in place today, built into how the platform runs.

In place today

Hosted on AWS

Synchrony runs on Amazon Web Services through Laravel Vapor, on infrastructure operated in AWS data centers.

In place today

Encrypted in transit

All traffic between tablets, browsers, and the platform travels over HTTPS with TLS.

In place today

Encryption at rest

Customer data is encrypted at rest in addition to TLS encryption in transit.

In place today

Business Associate Agreement (BAA)

We hold a signed BAA with AWS and sign one with every organization.

In place today

One facility, one boundary

Every major record is scoped to a single team. A global scope keeps one hospital’s data from being queryable by another.

In place today

Role-based access

Access is governed by authorization policies tied to surgical and team roles, so people see only what their role permits.

In place today

Authenticated sessions

We follow industry standards for authentication and authorization. Sign-in and session handling run on a maintained, widely used stack that is patched as updates are released.

In place today

Managed, encrypted OR tablets

We provide the fully encrypted tablets and manage them through a mobile device management tool.

In place today

Backup & disaster recovery

Backups run with point-in-time recovery, so the database can be restored to a specific moment.

In place today

Data retention & deletion

Data is retained for up to seven years. If a client asks for deletion immediately after cancelling, we oblige.

In place today

Incident response

We carry data-breach insurance and are obligated to notify customers of any breach or security incident.

In place today

Workforce training

Every employee completes strict HIPAA and security training before touching any customer data.

Have a security questionnaire?

Send it our way.

Request a Demo