Your patients trust you. You can trust us with their data.

The NeuroLogic platform handles sensitive patient health information every day. Keeping that information private, accurate, and available is built into how the platform works. Here is what we do to protect it.

Secure by design

Multi-factor sign-in

Encrypted end to end

Least-privilege access

Daily encrypted backups

Full audit logging

Independently tested

How we protect your data

Choose a topic to see what we do in that area.
Security

How we keep your data secure.

Protecting your patients’ information is a core part of our job. In practice, that means encryption everywhere, tight access controls, constant monitoring, and regular independent testing.
Your data is always encrypted

Your information is encrypted whenever it moves and whenever it is stored (TLS 1.2+ in transit, AES-256 at rest).

Strong sign-in with MFA

Every user has a unique login, and multi-factor authentication is required for our staff and available to every clinic.

Layered network defenses

Several layers of network protection block common attacks and keep unauthorized traffic out.

Watched around the clock
We monitor our systems continuously and keep detailed activity logs, so anything unusual gets noticed and looked into quickly.
We look for weaknesses

We regularly check our systems and our code for weaknesses, and bring in an independent team to test our security.

Every change is reviewed

No change reaches patients without a documented request, a peer review, and sign-off from our Lead Developer. 

Reliability

Built to stay up and running.

Clinicians use the platform during real appointments, so it is built to keep running. It sits on enterprise-grade cloud infrastructure with spare capacity built in, daily backups, and a recovery plan we test.
Enterprise-grade cloud hosting

The platform runs entirely on leading cloud infrastructure whose data centers hold their own independent security certifications.

Designed to handle failure
The infrastructure behind the platform has spare capacity built in, so a single failure does not take it down.
Daily, encrypted backups
We back up your data every day and keep those backups separate from the live system. We also test that we can restore from them.
A documented recovery plan
We keep a written disaster-recovery plan that sets the order systems come back in, so if something goes wrong we know what to restore first and how.
Ready for incidents

We have a clear plan for responding to security incidents, including how and when the right people are notified. 

Confidentiality

How we keep your data secure.

Patient information is private. Access follows a strict need-to-know model: clinicians see only their own patients, our staff cannot browse medical records, and every access is logged.
Need-to-know access
Everyone gets only the access their role requires. Anything not granted is denied by default, with no broad just-in-case permissions.
Clinicians see only their patients
A clinician can open records only for patients currently in their care. There is no general directory of everyone in the system.
Your data stays yours
Each customer organization can only reach its own data. One clinic cannot see another clinic’s information.
Identities kept separate
Patient identifying details are kept separate from the clinical health data, so the two are not stored together.
Our staff cannot see medical data

Apart from developers working under controlled conditions, our staff and admins cannot access patient files, names, or medical data. 

Everything is logged
Every user has a unique ID that is never reused, and every view or change to medical data is recorded. There is always a clear trail.
Access is reviewed regularly
Access is granted only with proper approval, reviewed regularly, and removed promptly when someone leaves or changes roles.
Trusted, trained people
Background checks, signed confidentiality agreements, structured onboarding, and mandatory security training apply to everyone on the team.
Compliance

Meeting the laws that apply to your patients.

Concussion care crosses borders, so our program is built to meet the major healthcare and data-protection laws your patients fall under. We keep it under continuous review.
HIPAA (United States)
We follow HIPAA’s rules for protecting health information, covering how it is safeguarded, who is accountable, and how any breach is handled.
PHIPA & PIPEDA (Canada)
We meet Canada’s federal and provincial health-privacy laws, so Canadian clinics and patients are covered.
GDPR (Europe)
This is our most mature program. We give health data the extra protection European law requires and publish our privacy notices in English and French.
FDA-cleared assessments
The clinical assessment tools built into the platform include FDA-cleared instruments.
Monitored continuously
Our controls are monitored continuously, rather than checked once a year.
Checked by outsiders
We bring in independent experts to test our security, carry cybersecurity insurance, take privacy advice from external legal counsel, and work only with vetted partners.
Privacy

Your data, used only for what it is for.

We collect and use personal and health information only for the care and services it is meant for. People keep control over their own data, and a dedicated Data Protection Officer runs our privacy program.
Privacy is governed formally

A dedicated Data Protection Officer runs our privacy program, and we publish clear privacy notices in English and French.

Health data gets extra care
Patient health information gets extra protection under privacy law, and we handle it that way at every step.
Clear agreements
We put proper data-protection agreements in place with our customers and our vendors.
You control your data
Requests to access, correct, or delete personal data are handled through a documented process, and we complete valid requests promptly.
Kept only as long as needed
Because concussions carry decades-long risk, clinical records may be kept as a lifelong health record where that is justified. Customer data is securely deleted after a contract ends.
Trust FAQs

The questions we hear most.

Answers to what clinicians, partners, and security teams ask us most. If you want more detail, we will cover it on a demo.
Is my data encrypted?
Yes, always. Your data is encrypted while it travels (TLS 1.2+) and while it is stored (AES-256), and it stays that way throughout. Staff devices are encrypted too.
Only the people who need to. Clinicians see records only for patients in their care. Apart from developers working under controlled conditions, our staff and admins cannot access patient files, names, or medical data at all. Every access is logged.
Our program is built to meet HIPAA (U.S.), PHIPA and PIPEDA (Canada), and GDPR (Europe). Our controls are monitored continuously and independently tested.
Yes. We maintain BAAs with our subcontractors and with our cloud provider, and we can put an appropriate BAA or Data Processing Agreement in place where we act as a business associate or processor. Your implementation team will handle this with you.
Yes. Your data is backed up every day and kept separate from the live system, and we test that we can restore it.
Yes. Independent experts test our security regularly, and we check our systems and our code for weaknesses on an ongoing basis.
We have a documented plan for responding to incidents, including notifying the people and regulators who need to know, as the law requires. Our policy leans toward notifying early.
Through our documented data-request process. We complete valid deletion requests promptly, and customer data is securely deleted after a contract ends.
Yes. We can walk your security or procurement team through our documentation under confidentiality, as part of a demo or implementation call.
LET'S GET STARTED

Ready to book a demo?​

Pick your region and we will connect you directly to one of our representatives that will walk you through the various features of Complete Concussions software and show you the tools in action!