Security & Compliance
Built for patient data, not adapted to it
Every practice is accountable for protecting its patients’ information, and most of that accountability comes down to controls that either exist by default or do not. In NovoClinical they exist by default — there is no security tier to upgrade to.
Who can see what
Access is governed by role. Clinical, front-office, billing and administrative staff each see only what their role allows, and permissions are assigned per user and per clinic. When someone changes role, their access changes with it.
Staff sign in with their own credentials rather than a shared login, which means the audit trail can actually attribute an action to a person. Shared accounts are the single most common reason a practice cannot answer “who did this?”
Encryption, in transit and at rest
Everything travelling between a browser and the system is encrypted. Patient data is protected in storage as well, not only in transit — the two are different problems and both matter.
Audit trails
Key actions are logged: who did what, and when. Administrators can review that record when a question needs answering, whether that is an internal query, a patient request, or something more formal.
Because clinical and financial work happen in the same system, the audit trail covers both. You are not reconciling logs from two applications to reconstruct what happened.
Backups and continuity
Data is backed up regularly to support recovery and business continuity. This is handled centrally rather than being a task your practice has to schedule, verify and remember — which is where practices running their own servers most often come unstuck. See cloud hosting.
Nothing installed, nothing left behind
The system runs in a standard web browser. Nothing is installed on individual machines, so no patient data sits on the hard drive of a laptop that leaves the building or a computer that gets replaced. Updates are delivered centrally, meaning every clinic is on the current version — there is no practice running an old build because a machine was missed.
Certification
NovoClinical is ONC certified. The mandatory disclosures, associated costs, API documentation and Real World Testing documentation are all published in full — see certification and disclosures.
AI and your patient data
The AI features operate within the platform’s own protected environment. Patient information handled by the AI is subject to the same access controls, encryption and audit logging as the rest of the record, and the provider reviews AI-drafted content before anything is written into a chart. The AI drafts; a clinician decides.