SECURITY & TRUST

Know the scope.
Ask for the evidence.

A professional software evaluation looks at the data, the people, the connected services and the controls that apply to the actual implementation.

A clear starting boundary.

This public showcase uses synthetic demonstration records. Its business inquiry forms are separate from the clinical application and are not for patient documents or payment-card details.

For your customer environment

Production access, enabled modules, usage limits, agreements and acceptance evidence are reviewed before activation. A website demonstration or a staff job title does not establish an access permission.

01 / PATIENT INFORMATION

HIPAA responsibilities
follow the data.

For a PHI-enabled pilot, the required BAA comes before patient information. Review the data flow, permitted use, relevant service providers and safeguards alongside your organization’s risk analysis and workforce practices. A BAA alone does not establish that the full program is complete.

  • Define permitted information, users and access responsibilities.
  • Review handling, retention, export and closure expectations.
  • Verify the applicable environment and service agreements.
  • Agree incident handling, recovery and an accountable contact.
HHS guidance on cloud services and HIPAA ↗
02 / PAYMENT INFORMATION

Payment processing
has its own scope.

Determine where card information is entered, transmitted and handled, and which party is responsible for each part of the flow. Using an outside processor does not by itself remove PCI DSS responsibilities. Applicable validation depends on the implemented payment channel and the requirements of the payment partners.

The public DMEStudios showcase does not collect card details. Discuss the accepted payment workflow separately from patient intake, documents and general notes.

PCI SSC guidance on outsourced payment processing ↗
03 / INDEPENDENT ASSURANCE

Read the report.
Understand what it covers.

SOC 2 examinations address controls relevant to security, availability, processing integrity, confidentiality or privacy within a defined scope. Ask which service is covered, what period was examined, what exceptions were identified and which responsibilities remain with the customer.

A provider’s report does not automatically cover every application built on that provider. No independently issued DMEStudios SOC 2 report has been verified for publication here. References to HIPAA, PCI DSS and SOC 2 explain the evaluation; they do not represent certification, validation or attestation of this product.

AICPA guidance on SOC reporting ↗
THE IMPLEMENTATION REVIEW

Make responsibility visible.

These are acceptance topics for your scoped deployment; agree the evidence and responsible owner before real-data access.

ACCESS

Who can do what?

Review named accounts, staff permissions, company boundaries, access removal and restricted actions.

DATA

Where does information travel?

Review protected transport, storage arrangements, connected services, retention and approved exports.

EVIDENCE

Can the decision be explained?

Review source documents, human approvals, recorded events, exceptions and the correction path.

RECOVERY

What happens when work fails?

Agree backup and restoration evidence, incident contacts, failure handling and service continuity.

Guidance reviewed October 5, 2026. Requirements depend on your organization, workflow and applicable agreements.