Security and compliance
Patient details, seen only by the people who need them.
Encryption
Patient details and appointments are encrypted in transit (TLS 1.2 or later) and at rest (AES-256).
Access by role
Reception, clinicians and managers each see only what their job needs. Clinicians can be limited to their own lists.
Audit log
Every time someone opens or changes an appointment or patient record, Quellow records who, what and when.
Your data region
Choose US, UK or EU hosting at setup. Patient data stays in that region, including backups.
Sign-in
Two-step sign-in for every account, automatic sign-out on shared desk computers, and single sign-on on the Group plan.
Private reminders
Reminder texts show the time and your practice name only, never the clinician, the reason for the visit or any results.
How Quellow supports each set of rules
HIPAA
For practices in the United States
A Business Associate Agreement, available on the Group plan
Access controls and automatic sign-out
An audit trail of access to patient information
Encryption of patient information in transit and at rest
GDPR and UK GDPR
For practices in the UK and the EU
A Data Processing Agreement with every customer
Hosting in the UK or the EU if you choose it
Export or delete a patient’s data when they ask
A current list of the sub-processors we use
Your part
Compliance is shared between us and your practice
Quellow gives you the controls. Your practice decides who has access, how long records are kept, and what a reminder text may say. Before you go live, we walk your compliance lead through each of these settings.
Quellow is not certified by any regulator, and this page is a summary of our controls, not legal advice. Ask us for the full security pack, including our Data Processing Agreement and sub-processor list.