Skip to content
Security

No patient data. By design.

Most dental software gets security wrong at the architectural level: it puts patient charts in the cloud, then defends the cloud. We removed the target instead. Patient charts stay on your server. Chartwright Cloud holds plan facts — payer, group, benefits — and nothing else.

Plain English

Plain English: your patient data never leaves your building. Chartwright OS and the Vitals engine run on your own server and read your practice-management database locally, read-only. The only data transmitted to Chartwright's hub is de-identified aggregate metrics — monthly totals by office and provider — plus a daily license heartbeat. No patient names, chart numbers, birthdates, or identifiers are ever transmitted or stored by Chartwright. Because only de-identified aggregates leave your network, no Business Associate Agreement is required for Vitals. You can export your complete data at any time — including after cancellation. We never hold your data hostage.

Found a vulnerability? Tell us: security@chartwright.io — we read every report.

  • Isolation

    Every practice's data — plan library included — lives in its own logical partition. There is no shared table where one office can see another's verifications by mistake.

  • Rotatable keys

    Encryption keys can be rotated on your schedule, not ours. Old data re-encrypts under the new key; the old key is destroyed.

  • Append-only audit

    Every plan write is attributed and permanent. You can see who verified what, when, from which payer call. Records can be corrected — never silently overwritten.

  • Snapshots

    Point-in-time snapshots of your plan library, held on your retention window. If something is wrong today, you can see exactly what it looked like last Tuesday.

  • Export anytime

    Your data is exportable in an open format on demand — not as a favor, and not for a fee. If you ever leave Chartwright, you take everything with you.

The honest BAA answer

Do we sign a BAA?

A Business Associate Agreement exists to govern what happens to Protected Health Information a vendor holds on your behalf. Chartwright Cloud is architected so that it never holds PHI: patient identifiers do not enter it, from any workstation, at any step. There is nothing for a BAA to govern in the cloud tier.

For the OS tier — which runs on your server, in your office, alongside your existing PMS — a BAA is available and appropriate. We will sign it. Ask us during your demo and we will send it in writing.

We do not display third-party compliance badges we have not earned. If we ever hold a formal certification, it will appear here with the certificate. Not before.

What lives where, in one list.

On your server
  • Patient identifiers and demographics
  • Clinical notes
  • Radiographs and photos
  • Treatment plans and history
In Chartwright Cloud
  • Payer, group, and plan identifiers
  • Per-CDT-code benefits, downgrades, frequencies
  • Verification attribution (who, when, call reference)
  • Nothing about your patients. Not their name. Not their birthdate. Nothing.