Named individual logins
One account per person, always. We will not use a shared login even if you offer one, because an audit trail that cannot name a person is not an audit trail.
A Business Associate Agreement is signed before anyone is given a login. Every person works under a named individual account in your own system. Nothing is exported, printed or copied to removable media. Access ends the same day a person comes off your account, and when an engagement ends we confirm in writing that we hold nothing of yours.
Most security pages list what a vendor has. Certificates are cheap and a badge proves nothing. This page lists what we will refuse to do, because a refusal is the only part of a security posture that actually costs something to keep.
One account per person, always. We will not use a shared login even if you offer one, because an audit trail that cannot name a person is not an audit trail.
No removable media, no printing, no exports, no personal email. Work happens inside your system and stays there.
A Business Associate Agreement is signed before anyone is given a login. Not after the first week. We will refuse access without it.
When somebody comes off your account their access ends that day, and we confirm it in writing.
When an engagement ends we confirm in writing that we hold nothing of yours. There is no archive on our side.
What was done, the numbers, and what went wrong. Including the weeks that went badly, because those are the ones worth reading.
No offshore vendor can promise you that a determined person cannot memorise a screen. Anyone who tells you otherwise is selling. What we can promise is that the account is named, the access is minimal, the floor is supervised, and every change is in writing, so that if something did go wrong you would be able to prove who, when and what. That is what an auditor asks for.
Yes, and before anyone is given a login rather than after the first week. If a vendor is willing to start work before the BAA is signed, that tells you what their compliance is worth.
There is no such thing as HIPAA certification. No government body certifies anyone, and any vendor showing you a HIPAA certificate has bought a logo from a training company. What matters is the signed BAA, the technical and administrative safeguards, and whether the controls survive a bad week. Ours are listed on this page and you are welcome to audit them.
In your system, where it already is. We do not copy it, mirror it, warehouse it or process it through anything of ours. There is no Soft Home Global database with your patients in it, which is the only genuinely safe answer to this question.
Phones are not permitted at the desk. The floor is supervised and camera-covered. This is a real risk and no vendor can honestly claim to have eliminated it, so we control it and we do not pretend otherwise.
Their access to your system ends the same day and we confirm it to you in writing. You can also revoke it yourself at any moment, because the login is yours and was issued by you.
Access is revoked and we confirm in writing that we hold nothing of yours. Since nothing was ever copied out, there is nothing to destroy and nothing to certify the destruction of.
Anything not answered here, write to ops@softhomeglobal.com and it will be answered plainly, or read how an engagement actually starts.
Three ways to check us before you commit to anything.
Next step
Twenty minutes on a call is enough to tell whether this fits. If it does not, I will say so.
Or write to ops@softhomeglobal.com