PeptIQ Provider Help

Search provider help

Search articles by title, summary, or section headings

On this page

Security practice

Protect data and use the audit trail

Apply consent, least privilege, and traceable workflows to sensitive clinic operations.

7 min readSecurity and compliance
View as Markdown

Protect patient information

  • Use individual accounts and protect authentication factors; complete email MFA when your organization requires it.
  • Access only patients associated with the selected clinic and only for legitimate work.
  • Respect the patient’s active consent scopes on every clinical surface.
  • Do not paste sensitive patient data into unapproved support channels or external tools.
  • Patient detail reads are rate limited; repeated bulk scraping triggers alerts.

Understand audit evidence

The console records access and operational events with context such as organization, actor, patient, resource, action, and time. Organization admins page the dashboard access audit log and filter by team member, resource, action, and date. Those filters use stored metadata, not patient names or note text. Audit data helps investigate who accessed or changed information, but it does not replace your organization’s complete compliance program.

  1. 1Identify the patient, actor, resource, and time window under review.
  2. 2Preserve relevant identifiers and avoid altering the affected workflow.
  3. 3Escalate suspected inappropriate access through your security process.
  4. 4Use the Security & Compliance footer link for platform security information.

Export and copy protections

  • Patient roster tables disable text selection and hide from browser print to reduce casual copying.
  • Rate limits apply to patient detail API reads per staff member per hour.
  • MFA may be required before clinical panels load when your organization enables it.
  • Settings and grant changes are recorded in the settings audit trail.