Security & HIPAA
We measure efficiency, not the patient chart.
Synchrony tracks how long each step of a surgical case takes and who owned it. No patient names, no medical record numbers, no diagnoses, no charts. Tracking how efficiently a room runs doesn’t require any of them, so we don’t collect them. It is a standalone platform with no connection to your EHR.
0
patient records stored
0
EHR integrations required
AWS
hosted on industry standard platform
BAA
signed with every customer
There is no patient data in Synchrony
A case in Synchrony is a start time, a set of intervals, the roles that owned them, and a room number. That is the whole record. Cases are identified by a short number like Case #4417, with no name attached to it. We are not an electronic medical record and we do not connect to one, so the information a chart holds never reaches us.
What Synchrony never stores
- Patient names or medical record numbers
- Diagnoses, clinical notes, or histories
- Imaging, labs, or pathology
- Billing or insurance information
- Anything resembling a full patient chart
All Synchrony stores
- Case flow intervals and their timestamps
- Surgical staff names and their assigned roles
- Schedule metadata: operating room, surgery type, date
- A per-case identifier, not a patient chart
- Delay reasons and performance metrics
Most HIPAA reviews come down to working out what a breach would expose. In our case it would expose no patient information at all.
We don’t connect to any systems you run
Synchrony is a standalone platform. It does not require any integration with your EHR or other clinical systems. There is no interface engine and no HL7 or FHIR feed to build, and we have no read access to your systems. Data enters in one place: the tablets in your operating rooms.
No integration to review
Your security team is evaluating one vendor. There is no connection into your clinical systems, so there is no interface to scope and no second review queue to sit in.
No IT project to schedule
You set up Synchrony by defining your own intervals, targets, and roles. Nothing has to be built or tested against another system first.
Nothing to unwind
Nothing was ever wired in, so stopping means switching off the tablets. There is no interface to decommission afterwards.
How we protect what we do hold
Staff names, schedules, and performance data still deserve protection. These are the controls in place today, built into how the platform runs.
Hosted on AWS
Synchrony runs on Amazon Web Services through Laravel Vapor, on infrastructure operated in AWS data centers.
Encrypted in transit
All traffic between tablets, browsers, and the platform travels over HTTPS with TLS.
Encryption at rest
Customer data is encrypted at rest in addition to TLS encryption in transit.
Business Associate Agreement (BAA)
We hold a signed BAA with AWS and sign one with every organization.
One facility, one boundary
Every major record is scoped to a single team. A global scope keeps one hospital’s data from being queryable by another.
Role-based access
Access is governed by authorization policies tied to surgical and team roles, so people see only what their role permits.
Authenticated sessions
We follow industry standards for authentication and authorization. Sign-in and session handling run on a maintained, widely used stack that is patched as updates are released.
Managed, encrypted OR tablets
We provide the fully encrypted tablets and manage them through a mobile device management tool.
Backup & disaster recovery
Backups run with point-in-time recovery, so the database can be restored to a specific moment.
Data retention & deletion
Data is retained for up to seven years. If a client asks for deletion immediately after cancelling, we oblige.
Incident response
We carry data-breach insurance and are obligated to notify customers of any breach or security incident.
Workforce training
Every employee completes strict HIPAA and security training before touching any customer data.
Have a security questionnaire?
Send it our way.