Security

Built for a chart, not a shopping cart.

You are putting patient names into someone else's software. That deserves a straight answer about what happens to them. Your practice is the covered entity, we sign a business associate agreement before you place an order, and the platform is built on that assumption from the database up.

A BAA before your first order

Signed with every practice before ordering begins, embedded in the agreement you accept at signup so there is no separate chase. It covers permitted uses, safeguards, subcontractors, breach notification, and what happens to your data if you leave.

Your patients are not in a shared pile

Your patients, orders, and payment methods are walled off from every other practice in the database itself, not just in application code. A query that forgets to scope by practice returns nothing at all, rather than somebody else's patient.

Everyone gets their own login

No shared passwords taped to a monitor. Prescribers and front desk staff get different permissions, so only a prescriber can touch the clinical fields. Two-factor is available on every account, and when someone leaves you deactivate them yourself, immediately.

A record that holds up

Who ordered what, for which patient, when it moved, and who changed it. If anyone ever asks your practice to account for an order, the answer is one screen, not an afternoon in an inbox.

Data handling

Who can see what.

Three parties touch an order. The walls between them are enforced by the software, not by a policy document somebody has to remember.

  • The pharmacy never sees your pricing. It gets what it needs to fill the order and nothing about what you paid or what we retained.
  • Practices never see each other. Cross-practice access is blocked at the database layer.
  • Encrypted in transit, on infrastructure hosted in the United States.
  • Network pharmacies are not our subcontractors. They receive treatment and payment disclosures as covered entities in their own right.
  • Export on termination. You can request an export of your practice's data for thirty days after your account ends. It is a contractual right in your agreement, not a courtesy.
Reporting a problem

Found something? Tell us.

Email support@aayuos.com with what you found and how to reproduce it. If you believe patient data has been exposed, say so in the subject line so it gets triaged immediately. We will acknowledge and tell you what we are doing about it.

Get started

Questions before you sign anything?

Send them over. We would much rather answer them now than halfway through onboarding.