Skip to content
Security

Built around records you cannot afford to lose

HyperCRM holds clinical records, so its security model is part of the product rather than a setting you switch on. Staff sign in with passkeys, every change is written to an audit log, and patient files sit in private storage that only a short-lived signed link can open.

The short version

Passkeys, not passwords

Self-hosted WebAuthn sign-in, bound to each person's device. No shared practice password to leak.

Roles and invitations

Owners and assistants, single-use expiring invites, and a last owner who cannot be removed.

A traceable record

Every change logged with its event, initiator and target; files served only via expiring signed links.

How staff sign in

Sign-in uses passkeys — the WebAuthn standard — hosted by HyperCRM rather than delegated to a third party. There is no shared practice password to circulate, write on a note, or leak, and each person's credential is bound to their own device.

Who can see what

A practice has owners and assistants. Owners manage the practice and its staff; assistants work in it. Staff join through a single-use invitation that expires, and the last owner of a practice cannot be removed or demoted — so a practice can never be locked out of its own records.

What gets recorded

Every change writes an entry to the action log: a typed event, who initiated it, and which record it touched. An edited clinical note or a deleted appointment can be traced back to a person and a time, which is what makes a record defensible months later.

How files are stored

Patient files — including imaging — are kept in private storage, never on a public URL. Access is checked against your session, and downloads are served through short-lived signed links that expire, so a copied URL does not become a permanent back door.

Public pages

Booking pages and form links are the only surfaces reachable without signing in. They are rate limited to blunt scripted abuse — as is every other endpoint, signed-in ones included — form links are single-use and expire, and reCAPTCHA can be enabled on top where a practice wants it.

Getting your data out

Every list exports to CSV from inside the app, and files can be downloaded at any time. There is no export fee and no waiting period — leaving is a supported action, not a negotiation.

Common questions

Patient records are encrypted in transit and at rest, files are stored privately and served through short-lived signed links, and every change is written to an audit log. Staff accounts sign in with passkeys rather than shared passwords.

Yes. Every list in HyperCRM exports to CSV from the app, and your files can be downloaded at any time. Your practice data belongs to you, and there is no export fee or waiting period — on either plan, during the trial, and after you cancel.

With passkeys — the WebAuthn standard, hosted by HyperCRM rather than delegated to a third party. There is no shared practice password to circulate or leak, and each person's credential is bound to their own device. That closes the most common way small-practice systems get breached.

Every change writes an entry to the action log with a typed event name, the person who initiated it, and the record it touched. An edited clinical note or a deleted appointment can be traced to a person and a time, which is what makes the record defensible later.

More in Company

Questions your compliance file needs answered

Ask whatever it needs. We would rather take the awkward question early than have you guess.

Ask us directly