HIPAA at ClinikEHR
Last Updated: September 18, 2026
ClinikEHR is built to hold patient information under the HIPAA Security Rule, and Bettar Platforms, Inc. signs a business associate agreement with every customer. This page sets out exactly which safeguards the software provides, what its records will and will not contain, and which obligations remain your practice's own.
We have tried to be specific rather than reassuring. No software can make a practice HIPAA compliant by itself: the Security Rule governs how a practice is run, not only the tools it runs on. What a vendor can do is provide the safeguards, keep the evidence, and be clear about where its responsibility ends — which is what follows.
On this page
1. Who is responsible for what
Under HIPAA your clinic is the covered entity. You decide what is collected, who may see it, and how long it is kept. Bettar Platforms, Inc., trading as ClinikEHR, is your business associate: we hold and process that information on your instructions and for no purpose of our own.
The business associate agreement takes effect when your account is created. You do not have to request it, negotiate it or sign it separately, and it is not reserved for larger plans. Where data protection law outside the United States also applies, the data processing agreement applies automatically alongside it, and our privacy policy explains what we hold about you as an account holder, which is a separate question from what you hold about your patients.
2. The safeguards built into ClinikEHR
The Security Rule's technical safeguards are at 45 CFR §164.312. Each row below names the standard and then what the product actually does about it.
| Standard | What ClinikEHR does |
|---|---|
| Unique user identification§164.312(a)(1) | Everyone signs in as themselves. Every action is recorded against the person who took it, so a record's history names a human being rather than a shared login. |
| Emergency access§164.312(a)(2)(ii) | A clinician who needs a restricted record in an emergency can open it by giving a reason and a time limit. The access is recorded, and it appears in the clinic's access report for review afterwards. |
| Automatic logoff§164.312(a)(2)(iii) | Sessions expire on their own. An unattended screen does not stay signed in indefinitely. |
| Encryption and decryption§164.312(a)(2)(iv) | Health information is encrypted while it travels and while it is stored, including in backups. |
| Audit controls§164.312(b) | Creating, changing, deleting and viewing a clinical record are all recorded, with the person, the record and the time. The history is kept for seven years. |
| Integrity§164.312(c)(1) | A clinical record is never quietly overwritten. The audit trail shows that it changed, when, and who changed it. |
| Person or entity authentication§164.312(d) | Sign-in is by password or passkey, and a clinic can require two-factor authentication for its staff. Where a clinic requires it, health information can only be opened from a session that has passed the second factor. |
| Transmission security§164.312(e)(1) | Every connection to ClinikEHR uses TLS 1.2 or better — the older versions of the protocol are refused outright, not merely discouraged. Traffic between our own systems is separately encrypted and authenticated, and never crosses the public internet unprotected. |
Physical safeguards (§164.310) cover the buildings the data sits in. ClinikEHR runs entirely in the cloud, so those controls are met by the infrastructure we build on, which is certified to recognised security standards and covered by its own business associate agreement with us. The workstations your staff use are yours to secure — see section 8.
3. What the audit trail records — and what it never records
§164.312(b) requires a record of activity in systems holding health information. In ClinikEHR that record is written as the work happens, not reconstructed afterwards. It captures who acted, which record they acted on, what they did and when — including views, not only changes, because reading a record is the disclosure most often asked about later.
What it never contains. The audit trail holds references to records, not their contents. Patient names, dates of birth, addresses, insurance numbers, diagnoses and the text of clinical notes are never written into it. This is deliberate: a history of who touched a record should not become a second copy of the record, readable by anyone reviewing access.
Who can read it. Owners and managers can. Ordinary staff cannot read the audit trail, including their own entries. How long it is kept: seven years.
4. Encryption
Information is encrypted on the way to us and while it is held, including in backups. Browser connections require TLS 1.2 or better and a current browser negotiates TLS 1.3; the older versions of the protocol are refused. Connections continue to be encrypted and verified between our own systems after they arrive, so the protection does not stop at the front door. Keys are managed by our infrastructure provider using hardware validated against the federal cryptographic standard that HIPAA guidance points to.
This matters beyond good practice. Under 45 CFR §164.402, properly encrypted information whose keys have not been compromised is secured, and its loss is not a reportable breach. That safe harbour is one of the few places where an engineering decision changes a clinic's legal exposure directly.
5. Who can open a record
HIPAA's minimum necessary standard (§164.502(b)) says people should reach the least information their job requires. ClinikEHR gives you several ways to draw that line, and enforces each of them where the data is held rather than merely hiding controls in the interface:
- One clinic cannot see another. Every record belongs to a clinic, and that boundary is enforced on every request. Working in two clinics means two separate sets of access, not one merged view.
- Roles and permissions. Owners, managers and staff see different things, and individual abilities can be granted or withheld per person.
- Assigned clients. A record can be restricted to the people actually looking after that patient, so a colleague elsewhere in the practice does not see it in passing.
- Sensitive records. Notes and documents on particularly sensitive subjects can be marked so that they are withheld from people who are not entitled to them, including in exports and in what a patient's proxy can see.
- Emergency access. When care requires it, a restricted record can still be opened, with a reason and a time limit, and the access is recorded for review.
Which of these are included on which plan is set out on the pricing page.
6. Your patients' rights
The Privacy Rule gives patients rights that a clinic must be able to honour. Some are answered by the product; others remain yours to decide, and the table says which is which.
| Right | What ClinikEHR does |
|---|---|
| Access a copy of their record§164.524 | Patients sign in to the client portal to read their documents, results and visit history, and to download what you have shared with them. |
| Request a restriction§164.522 | A patient can ask, from the portal, that a part of their record be restricted. The request reaches the clinic as a decision to make and record, not an email to lose. |
| An accounting of disclosures§164.528 | Disclosures are recorded as they happen, so the list a patient is entitled to can be produced from the record rather than reconstructed from memory. |
| Know who opened their record§164.524 | Patients can see which members of the clinic viewed their record, and when — the same history the clinic's own access report is built from. |
| Confidential communications§164.522(b) | Each patient's contact details and reminder preferences are held per clinic, so you can reach someone the way they asked to be reached. |
| Breach notification§164.404 | If information held on your behalf is involved in a breach, we notify you so you can meet your own notice obligations. Section 7 sets out the timeline. |
| Notice of privacy practices§164.520 | Your clinic issues this to its own patients. ClinikEHR does not publish a notice on your behalf. |
| Request an amendment§164.526 | Your clinic handles the request and decides it. ClinikEHR keeps the record history you need to show what was changed and when. |
7. If something goes wrong
A breach is an impermissible use or disclosure of unsecured health information. Our commitments are in the business associate agreement; the working timeline is this:
| Phase | When | What happens |
|---|---|---|
| Containment | Immediately | We contain the incident and preserve the evidence needed to work out what happened. |
| Assessment | Within 72 hours | We establish whether health information was actually reached, and whose. |
| We notify you | Without unreasonable delay | You are the covered entity. You cannot meet your own deadlines unless we meet ours first. |
| Notice to individuals | Within 60 days | Affected individuals are notified in writing — by your clinic, with what we have given you. |
| Notice to HHS | Within 60 days | Reported at hhs.gov/hipaa. Breaches affecting fewer than 500 individuals are reported in the annual submission. |
| Notice to media | Within 60 days | Where a breach affects 500 or more individuals in a state or jurisdiction. |
8. What HIPAA still asks of your practice
These are the obligations no vendor can discharge for you. We list them because a compliance page that mentions only the supplier's side leaves the reader with a false impression of what buying the software achieves.
- Name a security officer, in writing, and keep that designation current.
- Run and document your own risk analysis, covering how your practice works — not only the software it uses.
- Train your workforce on HIPAA, and keep the training records.
- Set your own minimum-necessary policies, then reflect them in the roles and permissions you grant here.
- Secure the devices your staff use: screen locks, disk encryption, and no shared accounts.
- Sign a business associate agreement with every other vendor that touches patient information.
- Remove access promptly when someone leaves.
ClinikEHR is designed to make the evidence for several of these easy to produce — the access history, the record of who was granted what, and the export a review needs. Producing it is still something your practice has to do.
9. Questions
Write to [email protected]. If you are completing a security review or a vendor assessment, say so and tell us the deadline — those are answered by a person, not a form.
This page explains how ClinikEHR supports compliance with the HIPAA Security and Privacy Rules. It is not legal advice, and it is not a determination that any particular practice is compliant.