Your patients' records, kept safe.
We protect your patients' records the way we would want ours protected. The audits and the paperwork are done before you ask.
Independent auditors check our work.
Ask us for the reports. We share them under NDA with customers and hospitals considering us.
What protects your data every day.
Encrypted always
Records are encrypted when stored (AES-256) and when sent (TLS 1.3). Enterprise plans get their own keys.
One login
Staff sign in with the login your hospital already uses (SAML or OIDC). Enterprise plans can add and remove staff automatically (SCIM).
Who can see what
Set what each role can see and do, down to a single record. Every change to access is recorded.
A record of every action
Who did what, and when. Every read, write and consent. Search it, filter it, export it.
Unusual activity alerts
Odd sign-ins, exports or bulk actions alert your admins right away.
Your data stays yours
Each hospital's data is kept apart from every other hospital's. Enterprise plans can have their own database.
Choose where data lives
US, EU, or your own cloud. We can keep a copy in a second region.
Watched day and night
We monitor 24/7 and page an engineer for any live problem. We aim for 99.99% uptime.
Finding weak spots
We scan our code and its parts all the time. Outside experts test us four times a year.
The documents your procurement team will ask for.
BAA & DPA
We sign these when you join if you handle patient health data or data on people in the EU.
Checking us out
Our list of suppliers, security questionnaires and SOC 2 reports. Available under NDA.
If something goes wrong
We tell you within 24 hours. For the most serious events, you get a full report within 5 business days.
Agreements and policies.
Privacy policy
What we collect, why, and how long we keep it. What rights you have over it. We collect as little as we can. Most usage data never leaves your hospital's account.
Terms of service
The contract between you and Oncominder. Written to be read, with a short plain summary of each part.
Business Associate Agreement (BAA)
We sign this when you join if you handle patient health data. When HIPAA changes, we update it. You do not have to ask.
Data Processing Agreement (DPA)
We sign this if you hold data on people in the EU. It comes with our list of suppliers and the EU Standard Contractual Clauses.
Need our SOC 2 report?
Sign a one-page NDA. We will send the latest report, the outside security test summary and our supplier list in one zip file.
