HIPAA-Compliant SNF EHR Security | Otangeles Notes+
SECURITY & COMPLIANCE

Built to handle PHI the way your compliance officer expects.

Clinical documentation and billing data demand more than a features list. Here is how Otangeles Notes+ handles protected health information.

HIPAA-COMPLIANT WORKFLOW BAA AVAILABLE SOC 2 · AUDIT IN PROGRESS
HOW PHI IS HANDLED

Six commitments, in plain language.

Encryption everywhere

PHI is encrypted in transit (TLS) and at rest. There is no mode of the product where patient data travels or sits unencrypted.

Role-based access

Providers, the scribe team, billers, and administrators each see the work that's theirs — access follows the role, not the login.

Full audit trails

Every draft, edit, handoff, signature, and claim action is logged and traceable — who did what, when, on which encounter.

Provider-in-the-loop AI

AI drafts and organizes — it never signs. Every note requires provider review and signature, and AI output is always labeled as a draft.

Your data, exportable

The practice owns its notes, claims history, and operational data. Export at any time — no lock-in by hostage-taking.

BAA & compliance posture

We operate as a HIPAA business associate and sign a BAA with every practice. A SOC 2 audit is in progress; we'll share status and reports on request.

FOR YOUR REVIEW

Bring your compliance officer. We'd like that.

Security review is part of every serious purchase in healthcare. We'll provide our security overview, BAA template, and SOC 2 status directly — and answer your security questionnaire.

Request the Security Overview Book a Demo
What we share in a security review
Security & architecture overview
BAA template for legal review
SOC 2 audit status & timeline
AI governance & provider-review policy
Completed security questionnaires

Security questions? Ask them early.

We'd rather clear your review board before the demo than after it.

Contact Security Book a Demo