Security & confidentiality

What we can see, and what we can't.

You are a medical, dental or law practice. Before you let anyone near your systems you need a straight answer about access, storage, and what happens if you want us gone. Here it is, without the security-theatre language.

01 — Access

An audit needs no system access at all.

The Operations Audit runs on interviews, observation, and a review of what you are paying for. If you would rather we never touch a system, the audit still happens and the report is still complete. Access is an option, not a requirement.

Where you do grant access, it is scoped as tightly as the work allows:

  • Read-only by default. We request the narrowest permission that lets the workflow function. Write access is only requested where the workflow cannot exist without it, and we tell you exactly which action needs it.
  • Connected through OAuth. You authorise from inside your own account. We never ask for and never store your password.
  • Revocable by you, instantly. You remove our access from your own settings page without asking us first. Nothing about that requires our cooperation.
  • Per-workflow, not blanket. Access granted for invoicing does not become access to patient records or case files.
02 — Storage

We are a processor, not your system of record.

Your EMR, your practice management system, your case management platform: those stay the source of truth. Our systems read from them, act, and write results back. We are not building a shadow copy of your practice.

  • Encrypted in transit and at rest. Standard TLS in transit, encrypted storage on disk.
  • Minimum retention. We hold what a workflow needs to run and nothing beyond it. Logs and intermediate data are pruned on a schedule, not kept indefinitely.
  • Infrastructure we control. Workflows run on servers we own and administer, not on a shared consumer platform. Each client is isolated with their own credentials.
  • Return and deletion on exit. When an engagement ends, you get your data and documentation, and we delete our copies. Ask us to confirm it in writing and we will.
03 — AI and model use

Your data is never used to train a model.

Parts of our workflows use language models to read documents and classify them. That work happens through commercial API agreements where the provider is contractually barred from training on the content submitted.

  • No training, ever. Not by us, not by our providers. This is contractual, not a preference.
  • No consumer AI tools in the loop. Your practice data does not get pasted into a chat window by a human on our side.
  • A human approves anything that matters. Invoices, outbound correspondence, and anything client-facing is queued for a person to approve before it leaves. Automation prepares the work. It does not sign off on it.
04 — Regulatory posture

HIPAA-aware. SOC 2 principles, not SOC 2 certified.

We would rather tell you this plainly than let you find it out later.

  • HIPAA. Where an engagement touches protected health information, we operate under a signed Business Associate Agreement and standard PHI handling protocols. If you do not want PHI in scope, we design the workflow so it never is.
  • Legal confidentiality. For law practices, we work under an engagement-specific confidentiality agreement covering client files, matter data, and privileged material. We are set up to sign yours rather than insist on ours.
  • SOC 2. Our systems are architected to SOC 2 principles: least-privilege access, encryption, audit logging, and documented change control. We are not formally certified, and we will not claim to be. If certification is a hard requirement for you, say so on the first call and we will tell you honestly whether we are the right fit today.
05 — Ownership

No lock-in. The systems belong to you.

Everything we build is documented in plain language and handed over. If you want to run it yourself, take it. If you want to hand it to another firm, take it there. We do not hold your workflows hostage as a retention strategy, and we do not take referral fees from software vendors.

We are trying to make ourselves unnecessary, then stay close in case you want a second opinion.

06 — Questions

Ask us anything before you sign.

If your practice has a security questionnaire, a compliance officer, or an IT vendor who needs to review us, send them our way. We would rather answer forty questions before an engagement than one after it.

Email joe@collinaconsulting.com, or raise it on the discovery call.

Book a discovery call →
Last updated August 2026. This page describes how we operate. Specific terms for your engagement are set out in the engagement agreement.