Audit & compliance
Access down to the tab.
A tech, a biller, a clinical director, and an owner should not see the same chart. Permissions are set per role, per program, and per section of the record — including the parts protected under 42 CFR Part 2.
Multi-entity aware. A clinician at one site doesn't see another site's patients.
The matrix
A tech, a biller, and a clinical director should not see the same chart.
Access is set per role and per section of the record, then scoped to a program or a billing entity. This is the actual grid, and an administrator can produce it on demand for an access review.
| Record section | Clinician | Tech | Billing | Supervisor | Owner |
|---|---|---|---|---|---|
| Demographics | Edit | View | Edit | Edit | Edit |
| Clinical notes | Edit | None | None | Edit | View |
| Treatment plan | Edit | View | None | Edit | View |
| Medication & eMAR | View | Edit | None | View | None |
| Claims & remittances | None | None | Edit | View | Edit |
| Part 2 protected records | Edit | None | None | View | None |
| Payroll & HR | None | None | None | View | Edit |
| Audit log & exports | None | None | None | View | Edit |
Scope
A role is not just what you can see. It is where.
Groups running several clinics and several billing entities need a clinician at one site not browsing another site's census. Scope is applied on top of the matrix, so the same role behaves differently depending on where the person works.
Limit a role to outpatient, PHP, or the residential unit — so a day-program clinician does not see the detox census.
Multi-entity groups keep staff, patients, and claims separated at the tenant level rather than by convention.
Optionally narrow a clinician to their own caseload, so the chart list is the people they actually treat.
You will be asked to prove this
An access review report is a standard survey request.
Accreditors ask who can see what. So does a breach investigation. Producing that grid should take a minute, not a conversation with an engineer — which is why the matrix is a report, not a config file.
Works with
It runs on the same record as the rest of the platform.
Audit & compliance
42 CFR Part 2 handling
Part 2 protects SUD treatment records more tightly than HIPAA, and it governs what you can disclose, to whom, and with which consent.
Read more →Audit & compliance
Activity log
An immutable record of who did what and when, across the whole tenant.
Read more →Audit & compliance
Trust center
Where the data lives, who can reach it, how it is encrypted, and what happens if something goes wrong.
Read more →Get started
Start today, or take a look first.
Create an account in minutes. Or book a 30-minute walkthrough.
