Everything we claim, with the receipt attached.
Most of what a provider in this category asserts cannot be checked. These pages exist because the assertions on the rest of this site should be checkable, including by somebody trying to catch us out.
Our service level commitments
Published response targets tiered by clinical severity, a 15-minute security containment commitment, RPO and RTO, and a service credit when we miss. Exactly one comparable provider publishes a response number at all, and it is an average.
Live metrics
Rolling 90-day operating figures with the methodology stated for each, updated monthly. Includes the dollar value of SLA credits we issued, and the two P1 targets we missed.
Case studies
A ransomware recovery, a twelve-practice DSO integration, and an OCR data request answered in nine business days. With before and after numbers, including the ones that took longer than we wanted.
How to evaluate a healthcare IT provider
Eleven questions to ask any IT company that touches your ePHI, with the citation behind each. Written to be used against us as well as against your incumbent.
Who we are not a good fit for
Six situations where we will decline the engagement, and what we recommend instead. Publishing it costs us deals and saves everyone a month.
Security and trust
Our SOC 2 Type II, the full subcontractor list with BAA status, our incident notification commitment to clients, and the entire technology stack we run.
The table nobody else has.
If you only read one thing on this site, read this. It is the entire service level commitment, including what you get when we miss.
EHR or practice management unavailable, a site offline, suspected ransomware, imaging down.
A clinician or front-desk user cannot see patients.
Functional but impaired.
New user, hardware, access change.