Security & privacy
Behavioral health records deserve more than a locked door
A resident's diagnosis, behavior history, and family circumstances are among the most sensitive records anyone keeps. Here is how Dacnus protects them, and what to ask us before you decide.
How PHI is protected
Encrypted field by field
PHI is encrypted at rest with AES-256-GCM at the field level, not just the volume it sits on. A database file lifted wholesale is not a readable record.
Access scoped to the role
Staff accounts carry a role that decides what they can reach, with least-privilege defaults. A billing account does not open a therapy note.
Sessions that close themselves
Inactive sessions expire and require signing in again, so a screen left open on a shared workstation does not stay open.
Multi-factor authentication
MFA is available for staff accounts and required for guardian access, with coverage reported on the compliance dashboard rather than assumed.
Audit trails
Evidence that accumulates instead of being assembled
Most organizations reconstruct their compliance story in the weeks before a review. A complete log means the story is already written.
- Every view, edit, and signature is written to an audit trail, including who, what, and when.
- Coverage spans clinical records, financial activity, and workforce data, not only the chart.
- Audit volume and access patterns surface on a dashboard, so gaps are visible before a survey rather than during one.
- Because the log accumulates as staff work, evidence for a licensing review is a report, not a reconstruction.
Families and guardians
Family access without opening the chart
Guardians need to stay close to a resident's progress. That is not the same as handing over the record.
- Guardian access is permissioned item by item, so a family member sees what you decided they see and nothing adjacent to it.
- MFA is required on guardian accounts.
- Access is re-authorized on a clock instead of persisting indefinitely after a placement ends.
What we say, and what we don't
What we build to
Safeguards designed to support HIPAA obligations, and a written policy library covering the administrative side: access control, breach notification, and incident response among them. The technical controls on this page are in the product today, not on a roadmap.
What nobody can hand you
HIPAA has no certification, so a “HIPAA certified” badge describes something that does not exist. We would rather say that plainly than let the word do work it has not earned. Where an independent assessment is what you need, ask us where that stands.
Bring your reviewer
The questions worth asking us
If your IT or compliance reviewer joins the evaluation, these are the areas they will want covered. We would rather answer them on a call, with your specifics in front of us, than publish a generic answer here.
Business associate agreement
What we will sign, and the terms we work under with your organization.
Hosting and data location
Where your data lives, who operates the infrastructure, and how backups are handled.
Breach and incident response
The written procedure, notification timelines, and who is accountable for each step.
Independent assessment
The current state of third-party testing and attestation, and what is planned.
Access reviews and offboarding
How accounts are provisioned, reviewed, and closed when staff leave.
Retention and deletion
How long records are kept, and what happens to them if you leave.
Put us in front of your compliance reviewer
Bring the person who has to sign off. We will walk the architecture, the audit trail, and the policy library with them directly.
