First Support EMR › Every security feature, in one list
Security features

Every security feature, in one list

What protects your agency's data inside the software, from the first sign-in to the record your state receives. All of it is included on every plan.

33 security controls are built into First Support EMR and run for every agency on every plan. For the agreement, hosting, subprocessors and incident notification, see Security & HIPAA.

Sign-in and accounts · Sessions · Browser protections · Data protection · Access and accountability · Hosting and compliance

Sign-in and accounts

Invitation-only accounts

No one can sign themselves up. Every login starts as a single-use invitation an administrator sends to one e-mail address.

Argon2 password hashing

Passwords are stored only as Argon2 hashes, the algorithm that won the Password Hashing Competition. Nobody, including us, can read a password back.

Account lockout

Five wrong passwords lock the account for fifteen minutes, which stops guessing against any one login.

Rate limits on sign-in

Sign-in and password-reset pages limit attempts per network address too, so trying many accounts from one place is slowed down as well.

One-hour, single-use reset links

A password-reset link works once and expires after an hour.

Password change signs out other devices

Changing a password ends every other session on that account, so a lost phone or a shared computer is cut off at once.

Revoked access is immediate

An administrator can switch off a caregiver, office user or family login, and that person is refused at the next sign-in.

Sessions

Automatic sign-out when idle

A session that sits unused for fifteen minutes signs itself out, which matters on shared office computers.

Twelve-hour session limit

Even an active session ends after twelve hours and has to sign in again.

Secure, per-agency cookies

Login cookies are sent only over HTTPS, are marked SameSite, and are scoped to your agency's own hostname.

Forgery protection on every form

Every screen that changes data carries a one-time security token, so another website cannot submit a form as a signed-in user.

Browser protections

Content Security Policy

The browser is told exactly which sources may load scripts, styles and images, which blocks injected code from outside.

HTTPS enforced (HSTS)

Browsers are instructed to use HTTPS for two years and never fall back to an unencrypted connection.

No framing by other sites

Pages cannot be embedded inside another website, which prevents click-jacking tricks.

Nothing leaks through links

Addresses inside the software are never passed to other sites as a referrer, and content types are never guessed.

Camera and microphone switched off

The browser blocks camera, microphone, USB and payment access; location is allowed only for the app's own EVV clock-in.

Safe file handling

Uploads are size-limited. Only images and PDFs open in the browser; any other file downloads instead of running, so a disguised web page cannot execute.

Sensitive pages are not cached

Medicaid forms, faxes and assessments are sent with no-store, so they do not stay in the browser's cache after sign-out.

Data protection

Encryption in transit

Every connection, from browser, phone, state aggregator API or SFTP, is encrypted with TLS. SFTP servers are checked against a pinned host key.

Encryption at rest

The database and its backups are encrypted on disk.

Field-level encryption

A caregiver's Social Security number, where a state requires it for EVV, is encrypted separately with a key kept outside the database and shown only as its last four digits.

Write-only secrets

Aggregator passwords, API keys and payment credentials can be entered and replaced but are never displayed again.

One database per agency

Each agency has its own hostname and its own database. No table is shared between agencies.

Least-privilege database access

The application connects with an account that can reach only its own tables.

Encrypted, automated backups

Backups run on a schedule, are encrypted, and restores are tested.

Access and accountability

Role-based access

Office staff, caregivers, and clients or family members each see only what their role allows. Administrators grant and remove individual capabilities, such as billing, per person.

Tamper-evident audit log

Every change records who did what and when. Each entry is chained to the one before it with a SHA-256 hash, so an edited or deleted entry is detected when the chain is verified.

Secrets kept out of the log

Passwords, tokens, signatures and Social Security numbers are redacted before anything is written to the audit log.

Write-once EVV records

A visit's original clock-in and clock-out times are never overwritten. A correction is a new record saying who changed it, when and why.

Hosting and compliance

Business Associate Agreement

We sign a BAA with every agency before any protected health information is stored.

AWS in the United States

The software runs on Amazon Web Services in the US, using AWS's HIPAA-eligible services.

Separate test and live connections

A state-aggregator test account cannot reach a live endpoint, and a live account cannot be used for certification tests.

Disclosed subprocessors

Every vendor that touches data is named on our Security page, and we tell you before adding one that handles PHI.

What we do not claim yet

  • Two-factor sign-in is not available today. Until it is, the lockout, rate limits, idle sign-out and per-device session controls above are the protection on each login.
  • SOC 2 and HITRUST: we do not hold either report today. A security questionnaire gets a written answer, and anything on this page can be shown on a screen-share.

Questions: [email protected] · Security & HIPAA · Privacy

See it in twenty minutes.

A screen-share of the working software, in your state's EVV format. No obligation.

Tell us where to reach you

Thank you.We will call to set a time, usually within one business day.