Security and Privacy – How We Protect Your Clinic's Data
Back Office Hub is built for healthcare operations teams. We take data security seriously and are transparent about what we do and do not do.
Encryption and Transport
All data is transmitted over HTTPS with TLS encryption in transit. File uploads are stored in encrypted cloud object storage (S3). We do not transmit data over unencrypted channels.
Access Control
Access is role-based. Only authorized members of your organization can view your clinic's records. Organization data is isolated: clinics cannot access each other's records. Platform administrators can view organizational data for support purposes only.
Authentication
Authentication is handled via OAuth. We do not store passwords. Sessions are managed with signed JWT tokens.
Payment Security
All payment processing is handled by Stripe, which is PCI-DSS Level 1 certified (the highest level of payment security certification). We do not store credit card numbers or banking details.
What We Do Not Store
- No patient health information (PHI)
- No clinical records, patient charts, or diagnostic data
- No personal health numbers or OHIP numbers
- No credit card numbers (handled entirely by Stripe)
Back Office Hub is not an electronic health record (EHR) system. It tracks operational compliance documents only: directives, policies, certifications, staff credentials, and agreements.
PIPEDA and Provincial Privacy Alignment
Back Office Hub follows practices aligned with the Personal Information Protection and Electronic Documents Act (PIPEDA). Because we do not store patient health information, PHIPA obligations related to PHI custody do not apply to the data within this system. We follow security best practices including encryption in transit, role-based access control, and organization-level data isolation.
Data Hosting
Data is stored on managed cloud infrastructure. For specific hosting location details, contact us at healthopsrx@gmail.com. We are transparent about what we can and cannot confirm regarding data residency.
Data Retention and Deletion
We retain your data for as long as your account is active. If you cancel your subscription and request deletion, we will remove your organization's data within 30 days. Backup copies may persist for up to 90 days before being purged.
Third-Party Services
- Stripe – payment processing (PCI-DSS Level 1)
- Resend – transactional email delivery (reminders, signature requests, notifications)
- Manus OAuth – authentication
Each third-party service has its own privacy policy governing how they handle data.
Operator
Back Office Hub is operated by SKR Nursing Professional Corporation, based in Ontario, Canada. For security or privacy questions, contact healthopsrx@gmail.com.