Skip to main content
Oncominder
FeaturesPricingSecurityAbout
Log inRegister
Security & trust

Your patients' records, kept safe.

We protect your patients' records the way we would want ours protected. The audits and the paperwork are done before you ask.

Standards we meet

Independent auditors check our work.

Ask us for the reports. We share them under NDA with customers and hospitals considering us.

HIPAA
We follow the HIPAA rules for people, buildings and systems. A BAA is included.
GDPR
Data can stay in the EU. You can ask us to delete it or hand it over. A DPA is available on request.
21 CFR Part 11
Electronic records and signatures that meet the rule. Every change is recorded: who, what and when.
SOC 2 Type II
Schellman, an independent auditor, checks our security every year.
ISO 27001
We run our security the way ISO 27001 sets out.
NIST 800-53
Our controls map to the NIST list for moderate-impact US federal systems.
How it works

What protects your data every day.

Encrypted always

Records are encrypted when stored (AES-256) and when sent (TLS 1.3). Enterprise plans get their own keys.

One login

Staff sign in with the login your hospital already uses (SAML or OIDC). Enterprise plans can add and remove staff automatically (SCIM).

Who can see what

Set what each role can see and do, down to a single record. Every change to access is recorded.

A record of every action

Who did what, and when. Every read, write and consent. Search it, filter it, export it.

Unusual activity alerts

Odd sign-ins, exports or bulk actions alert your admins right away.

Your data stays yours

Each hospital's data is kept apart from every other hospital's. Enterprise plans can have their own database.

Choose where data lives

US, EU, or your own cloud. We can keep a copy in a second region.

Watched day and night

We monitor 24/7 and page an engineer for any live problem. We aim for 99.99% uptime.

Finding weak spots

We scan our code and its parts all the time. Outside experts test us four times a year.

Paperwork

The documents your procurement team will ask for.

BAA & DPA

We sign these when you join if you handle patient health data or data on people in the EU.

Checking us out

Our list of suppliers, security questionnaires and SOC 2 reports. Available under NDA.

If something goes wrong

We tell you within 24 hours. For the most serious events, you get a full report within 5 business days.

Legal

Agreements and policies.

Privacy policy

What we collect, why, and how long we keep it. What rights you have over it. We collect as little as we can. Most usage data never leaves your hospital's account.

Terms of service

The contract between you and Oncominder. Written to be read, with a short plain summary of each part.

Business Associate Agreement (BAA)

We sign this when you join if you handle patient health data. When HIPAA changes, we update it. You do not have to ask.

Data Processing Agreement (DPA)

We sign this if you hold data on people in the EU. It comes with our list of suppliers and the EU Standard Contractual Clauses.

Need our SOC 2 report?

Sign a one-page NDA. We will send the latest report, the outside security test summary and our supplier list in one zip file.

Book a demoSee pricing
Oncominder

Hospital software and a patient app, in one place.

Product
FeaturesPricingSecurityRoadmapChangelog
Modules
ClinicalResearchPatient portalAdmin console
Company
AboutCustomersCareersPressRequest a demo
Legal
PrivacyTermsBAADPATrust center
© 2026 Oncominder, Inc.