Security

Security overview

This page describes the security posture of the public PowerChart90 deployment. It is not a SOC 2 report or penetration-test certificate.

Effective date: August 17, 2026 · Last updated: August 17, 2026

Current public posture: HTTPS transport, authenticated product gate, server-side credential checks, short-lived signed session tokens, and least-privilege function endpoints. Formal third-party audit reports are available to customers under NDA upon request when completed.

1. Architecture (high level)

2. Access control

3. Encryption

4. Subprocessors

5. Logging, retention, backups

Function invocations may produce operational logs (time, status, coarse metadata). Chart text is processed to fulfill the request and is not offered as a permanent clinical repository. Deletion requests: audit-defense@pdpmauditgroup.com. See Privacy Notice §5.

6. Code-table freshness (CMS / OIG)

PowerChart90 refreshes CMS ICD-10-CM billable codes and the HHS-OIG LEIE NPI set on a nightly schedule from public government downloads. The active vintage is shown in scan results and at /powerchart90/data/codes-meta.json. CPT® is not redistributed (AMA copyright).

7. Vulnerability management & testing

We perform ongoing code review of product changes. Independent penetration testing and formal certifications (for example SOC 2) are customer-request items; ask for the latest status under NDA. Absence of a public badge is not a claim that testing never occurs, nor proof of a specific certification.

8. Incident response

  1. Detect and contain suspected unauthorized access or disclosure
  2. Assess scope and legal notification duties
  3. Notify affected customers without unreasonable delay as required by the BAA and applicable law
  4. Remediate, document, and improve controls

Report suspected incidents to audit-defense@pdpmauditgroup.com with subject “Security incident.”

9. Customer responsibilities