Every security feature, in one list
What protects your agency's data inside the software, from the first sign-in to the record your state receives. All of it is included on every plan.
33 security controls are built into First Support EMR and run for every agency on every plan. For the agreement, hosting, subprocessors and incident notification, see Security & HIPAA.
Sign-in and accounts · Sessions · Browser protections · Data protection · Access and accountability · Hosting and compliance
Sign-in and accounts
Invitation-only accounts
No one can sign themselves up. Every login starts as a single-use invitation an administrator sends to one e-mail address.
Argon2 password hashing
Passwords are stored only as Argon2 hashes, the algorithm that won the Password Hashing Competition. Nobody, including us, can read a password back.
Account lockout
Five wrong passwords lock the account for fifteen minutes, which stops guessing against any one login.
Rate limits on sign-in
Sign-in and password-reset pages limit attempts per network address too, so trying many accounts from one place is slowed down as well.
One-hour, single-use reset links
A password-reset link works once and expires after an hour.
Password change signs out other devices
Changing a password ends every other session on that account, so a lost phone or a shared computer is cut off at once.
Revoked access is immediate
An administrator can switch off a caregiver, office user or family login, and that person is refused at the next sign-in.
Sessions
Automatic sign-out when idle
A session that sits unused for fifteen minutes signs itself out, which matters on shared office computers.
Twelve-hour session limit
Even an active session ends after twelve hours and has to sign in again.
Secure, per-agency cookies
Login cookies are sent only over HTTPS, are marked SameSite, and are scoped to your agency's own hostname.
Forgery protection on every form
Every screen that changes data carries a one-time security token, so another website cannot submit a form as a signed-in user.
Browser protections
Content Security Policy
The browser is told exactly which sources may load scripts, styles and images, which blocks injected code from outside.
HTTPS enforced (HSTS)
Browsers are instructed to use HTTPS for two years and never fall back to an unencrypted connection.
No framing by other sites
Pages cannot be embedded inside another website, which prevents click-jacking tricks.
Nothing leaks through links
Addresses inside the software are never passed to other sites as a referrer, and content types are never guessed.
Camera and microphone switched off
The browser blocks camera, microphone, USB and payment access; location is allowed only for the app's own EVV clock-in.
Safe file handling
Uploads are size-limited. Only images and PDFs open in the browser; any other file downloads instead of running, so a disguised web page cannot execute.
Sensitive pages are not cached
Medicaid forms, faxes and assessments are sent with no-store, so they do not stay in the browser's cache after sign-out.
Data protection
Encryption in transit
Every connection, from browser, phone, state aggregator API or SFTP, is encrypted with TLS. SFTP servers are checked against a pinned host key.
Encryption at rest
The database and its backups are encrypted on disk.
Field-level encryption
A caregiver's Social Security number, where a state requires it for EVV, is encrypted separately with a key kept outside the database and shown only as its last four digits.
Write-only secrets
Aggregator passwords, API keys and payment credentials can be entered and replaced but are never displayed again.
One database per agency
Each agency has its own hostname and its own database. No table is shared between agencies.
Least-privilege database access
The application connects with an account that can reach only its own tables.
Encrypted, automated backups
Backups run on a schedule, are encrypted, and restores are tested.
Access and accountability
Role-based access
Office staff, caregivers, and clients or family members each see only what their role allows. Administrators grant and remove individual capabilities, such as billing, per person.
Tamper-evident audit log
Every change records who did what and when. Each entry is chained to the one before it with a SHA-256 hash, so an edited or deleted entry is detected when the chain is verified.
Secrets kept out of the log
Passwords, tokens, signatures and Social Security numbers are redacted before anything is written to the audit log.
Write-once EVV records
A visit's original clock-in and clock-out times are never overwritten. A correction is a new record saying who changed it, when and why.
Hosting and compliance
Business Associate Agreement
We sign a BAA with every agency before any protected health information is stored.
AWS in the United States
The software runs on Amazon Web Services in the US, using AWS's HIPAA-eligible services.
Separate test and live connections
A state-aggregator test account cannot reach a live endpoint, and a live account cannot be used for certification tests.
Disclosed subprocessors
Every vendor that touches data is named on our Security page, and we tell you before adding one that handles PHI.
What we do not claim yet
- Two-factor sign-in is not available today. Until it is, the lockout, rate limits, idle sign-out and per-device session controls above are the protection on each login.
- SOC 2 and HITRUST: we do not hold either report today. A security questionnaire gets a written answer, and anything on this page can be shown on a screen-share.
Questions: [email protected] · Security & HIPAA · Privacy
See it in twenty minutes.
A screen-share of the working software, in your state's EVV format. No obligation.
