No patient data. By design.
Most dental software gets security wrong at the architectural level: it puts patient charts in the cloud, then defends the cloud. We removed the target instead. Patient charts stay on your server. Chartwright Cloud holds plan facts — payer, group, benefits — and nothing else.
Plain English: your patient data never leaves your building. Chartwright OS and the Vitals engine run on your own server and read your practice-management database locally, read-only. The only data transmitted to Chartwright's hub is de-identified aggregate metrics — monthly totals by office and provider — plus a daily license heartbeat. No patient names, chart numbers, birthdates, or identifiers are ever transmitted or stored by Chartwright. Because only de-identified aggregates leave your network, no Business Associate Agreement is required for Vitals. You can export your complete data at any time — including after cancellation. We never hold your data hostage.
Found a vulnerability? Tell us: security@chartwright.io — we read every report.
Isolation
Every practice's data — plan library included — lives in its own logical partition. There is no shared table where one office can see another's verifications by mistake.
Rotatable keys
Encryption keys can be rotated on your schedule, not ours. Old data re-encrypts under the new key; the old key is destroyed.
Append-only audit
Every plan write is attributed and permanent. You can see who verified what, when, from which payer call. Records can be corrected — never silently overwritten.
Snapshots
Point-in-time snapshots of your plan library, held on your retention window. If something is wrong today, you can see exactly what it looked like last Tuesday.
Export anytime
Your data is exportable in an open format on demand — not as a favor, and not for a fee. If you ever leave Chartwright, you take everything with you.
Do we sign a BAA?
A Business Associate Agreement exists to govern what happens to Protected Health Information a vendor holds on your behalf. Chartwright Cloud is architected so that it never holds PHI: patient identifiers do not enter it, from any workstation, at any step. There is nothing for a BAA to govern in the cloud tier.
For the OS tier — which runs on your server, in your office, alongside your existing PMS — a BAA is available and appropriate. We will sign it. Ask us during your demo and we will send it in writing.
We do not display third-party compliance badges we have not earned. If we ever hold a formal certification, it will appear here with the certificate. Not before.
What lives where, in one list.
- Patient identifiers and demographics
- Clinical notes
- Radiographs and photos
- Treatment plans and history
- Payer, group, and plan identifiers
- Per-CDT-code benefits, downgrades, frequencies
- Verification attribution (who, when, call reference)
- Nothing about your patients. Not their name. Not their birthdate. Nothing.