Skip to content
My Practice Analyst

Security

How we protect your numbers, in plain English. Each point below describes how the service works today.

We never receive patient records
We work from practice and location totals only. Files that contain patient names or other patient-level details are refused when they are uploaded, before anything is saved.
Encrypted in transit and at rest
Every page and upload travels over HTTPS, and browsers are told never to use a plain connection. Your data is stored with our hosting and database providers (Vercel, Supabase and Neon), which encrypt it at rest.
Each practice sees only its own data
Every page, download and upload checks which practice you belong to. Someone at one practice cannot open another practice’s figures or files, and financial figures stay hidden from each person until the owner turns them on.
Admin access needs two-factor sign-in
The administrator account behind the service must enter a code from an authenticator app on top of the emailed sign-in link. Without that code, admin tools stay locked.
Access is logged
Sign-ins, failed attempts, uploads, exports and admin changes are written to a log that cannot be edited or deleted from inside the app.
Our own accounts use two-factor too
The accounts that run the service, for hosting, code, the app database, the domain and email, all require two-factor sign-in.
Limits on repeated attempts
Sign-in links, uploads and this site’s inquiry form are rate limited, so repeated automated attempts are slowed down and turned away.

Found a problem?

If you think you have found a security problem, email us and we will reply. Please do not include patient information.

owen@mypracticeanalyst.com