Built like it holds what it holds.
Your EMR holds the most sensitive information your patients will ever hand anyone. Aminova is built accordingly — down to an audit trail that not even we can edit.
Audit trail · append-only — denials recorded too
Isolation at the database, not in the code
Every clinic’s records are separated by row-level security in the database itself — enforced beneath the application, on every table holding patient data. A bug in a screen cannot show one clinic another clinic’s patients, because the database refuses the read regardless of what the code asks for.
Security that survives a busy Tuesday
Controls staff route around are not controls. Two-factor is paired with remembered devices so the front desk is challenged monthly rather than every shift, and the second factor is demanded at the moments that matter — sending a prescription, exporting patient data, changing where the money lands, granting someone access.
Paperwork that actually covers you
A signed BAA with every clinic, on every plan, never as an upsell — plus BAAs in place with the infrastructure underneath us, so the chain of responsibility runs all the way down rather than stopping at our front door. Breach notification obligations are written into the agreement with real timelines, not left as a promise.
Encrypted, isolated, and minimised.
Encryption is table stakes. What matters more is that each clinic’s data is separated where it is stored, and that sensitive material is served in ways that cannot be shared by accident.
- ✓Encrypted in transit (TLS) and at rest
- ✓Row-level security on every table holding patient data
- ✓Documents and clinical photos stored privately — never public URLs
- ✓Files served through short-lived expiring links, not permanent ones
Data Layer
Isolation is enforced by the database, not by the screen you are on.
Who gets in, and what they can reach.
Most breaches are an account, not an exploit. Access is layered so a stolen password on its own is not enough, and so a compromised session cannot quietly do the worst things.
- ✓Two-factor authentication with backup codes
- ✓“Remember this computer” for 30 days, scoped to one member on one machine
- ✓Re-authentication required to prescribe, export, change payouts or grant access
- ✓Role-based access — the front desk sees scheduling, clinicians see charts
- ✓Account lockout after repeated failures, and a server-enforced idle timeout
Sign-In Controls
A remembered device never substitutes for the password.
Everything is written down.
HIPAA expects you to be able to say who looked at a record. The audit trail records access and change across the system, and it exports — because the version an investigator wants is a file, not a screenshot.
- ✓Every view and change recorded with who, what and when
- ✓Failed sign-ins and failed second factors logged
- ✓Sign-ins from outside your usual locations flagged
- ✓Controlled-substance dispensing logged separately and exportably
Audit Trail
You can answer “who opened this chart” without calling us.
The paperwork behind the software.
Technical controls are half of HIPAA. The other half is contracts, vendor management and knowing what happens when something goes wrong.
- ✓A signed BAA with every clinic, included on every plan — not an upgrade
- ✓BAAs in place with the infrastructure providers underneath us
- ✓Breach notification obligations written into the agreement
- ✓EPCS: a DEA-required third-party audit of the application is completed before any clinic transmits controlled substances, and repeats every two years
Compliance Posture
We would rather tell you what is pending than let you assume.
How it works
Three moves, one platform.
Encrypted in transit and at rest, with each clinic’s data isolated at the database level rather than by application logic.
Two-factor at sign-in, remembered devices so it stays usable, and re-authentication before anything high-risk.
Every view and change written to an audit trail that you can export, because "trust us" is not evidence.
The controls, in plain terms.
Your brand, one login, no stitched-together stack.
Encrypted throughout
In transit and at rest.
Tenant isolation
Row-level security on every PHI table.
Two-factor
With backup codes and remembered devices.
Step-up re-auth
Before prescribing, exporting or moving money.
Role-based access
Clinical, financial and scheduling, separated.
Idle timeout
Enforced by the server, not just the browser.
Audit trail
Exportable, because evidence beats assurance.
Private file storage
Expiring links, never public URLs.
BAA included
Every plan. Never an upsell.
Questions
Do we get a BAA?
Yes, with every plan, at no extra cost. A vendor charging extra for a Business Associate Agreement is charging you to let them handle PHI legally, which tells you how they think about it.
What about EPCS and the DEA?
Electronic prescribing of controlled substances requires a DEA-mandated third-party audit of the application. That audit is completed before any clinic transmits controlled substances electronically, and it repeats every two years. During onboarding we will tell you exactly where that stands for your clinic rather than leaving you to assume.
How is our data separated from other clinics?
By row-level security in the database, applied to every table holding patient data, plus per-clinic credentials for anything that ingests data from outside. It is enforced underneath the application, so an application bug cannot expose another clinic’s records.
What happens if there’s a breach?
The controls above are designed so it is hard to have one: tenants are isolated, the audit trail cannot be altered or deleted, and anything sensitive requires a second authentication. If something did happen, your notification rights are contractual — obligations and timelines are written into the BAA you sign on day one, not into a blog post. You would hear it from us, quickly, and the agreement already says how quickly.
Can we get our data out?
At any time, without asking us and without a fee, and it is written into the agreement rather than left as a promise. An EMR that holds your records hostage is a bad EMR regardless of how well it encrypts them.
See it in action.
A 30-minute walkthrough, configured for how your clinic runs.