Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

In development

Patient Trust Center is being built. It is not part of any plan today, and nothing on this page describes a capability you can use yet. The rest of the page describes the intended product. It is intended for the Pro plan.

See what ships today

Network · Patient Trust Center

Patients ask whether their records are safe. Nobody has a good answer to point at.

In development, and the least decided of the things we are building. The problem is real; what a truthful public compliance page should actually show is the open question.

In development·

HIPAA mapping

Where this fits in the HIPAA rules.

3 provisions this capability contributes to, each with the specific Patient Trust Center behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.

§164.520

Notice of Privacy Practices

Requires a covered entity to provide a notice of privacy practices, with prescribed content and its own distribution rules. Worth separating from this page's subject: a notice is a required document, and a public trust page is not required by anything. Whether one could sensibly host the other is an open question rather than a feature.

§164.522

Rights to request privacy protection

Gives individuals a right to request restrictions on uses and disclosures. A practice must have a way to receive such a request and a process for considering it; nothing requires that route to be a public web page, and nothing here provides one today.

§164.524

Access of individuals to PHI

Gives individuals a right of access to their PHI, and requires the practice to have a route for receiving such a request and acting on it. A public Trust Center is the intended home for that route. It is not the route today — an access request currently reaches a practice the way anything else does, and building the public surface does not by itself discharge the obligation to answer.

What it does

The public surface for verifiable compliance.

Patients are increasingly aware of breach risk. The healthcare sector has held the top breach-cost spot for thirteen years. Patients searching for a new provider increasingly check what they can verify about the practice's privacy standing before they walk in.

The intended product is a public, branded page on the practice's own domain showing what a patient can verify about its privacy standing, kept current from platform state rather than written once and forgotten. What that page should actually show is the unsolved part, and it is discussed below rather than settled here. The comparison worth beating is the static “we take privacy seriously” paragraph every practice already has.

It is also intended to be where a patient starts a request — access, amendment, restriction, communication preference — so the request arrives in one place instead of by phone or email. That routing is designed and not built; Patient Management is the queue it would arrive in.

How it works

5 mechanisms we intend to build.

01

The problem, before the product.

Patients do occasionally ask what a practice does with their information, and the honest answer today is a privacy notice nobody reads. A practice that has actually done the work has no way to show it that is any more credible than one that has not. That gap is what makes this worth building.

02

What a public page should show is unsettled.

Publishing a raw compliance score is the obvious idea and probably the wrong one. A number without its composition invites the same misreading a completion percentage does, and a practice mid-way through its assessment would be penalised for being honest about it. Working out what is both truthful and useful to a patient is the actual design problem here, and it is not solved.

03

The temptation to avoid.

Every trust page in every other category ends up as a wall of badges. If this ships, the thing that would make it worth having is that a patient can see something specific about this practice rather than a template with a logo dropped into it — and that is harder than it sounds, because most of what a practice does well is not visible from outside.

04

What is live today.

Nothing here is. Practices on Patient Protect can already point a patient at a governed exchange rather than an email address, and the Patient Protect Score exists inside the platform for the practice's own use. A public verification surface is not part of any plan and is not in the trial.

05

Trust badge for practice's main site.

An embeddable badge on the practice's main site, linking through to the Trust Center, is part of the intended design. Like the rest of this page it does not exist yet, and it inherits the unsolved question directly above: a badge that shows a bare number has the same misreading problem the score itself does.

Who this is for

Built for the practices that need it most.

Practices whose patients ask.

Some do, particularly after a breach makes the news locally. Having nothing to point at other than a privacy notice is unsatisfying for everybody in the conversation.

Practices that compete on trust.

Behavioral health, reproductive care, anywhere the sensitivity of the record is part of why a patient chose you. This is the audience the idea exists for, and it is also the audience most likely to notice if what we publish is thin.

Practices watching this space.

If a public trust page is something you want, the useful information is that it is in development, that it is not in any plan or the trial, and that what it should show is still an open question.

What you get

3 outcomes it is meant to produce.

In development.

Not in Basic, not in Pro, not in the trial.

The design question is open.

What a truthful public compliance page shows is not settled.

Live today: the governed channel.

Patients can be brought into Secure Messaging now, on Basic.

FAQ

What people ask first.

4 questions cover most first-time evaluations. See all FAQs →

Can I use this today?
No. The Patient Trust Center is in development. It is not part of Basic or Pro, it is not in the trial, and it is intended for Pro when it ships — an intention rather than a commitment about timing or packaging.
Would it publish our compliance score?
Undecided, and we are sceptical of the obvious version. A number published without its composition invites exactly the misreading a completion percentage does, and a practice partway through an honest assessment would look worse than one that had not started. Solving that is the design problem, not the implementation.
Is a public trust page a HIPAA requirement?
No. §164.520 requires a notice of privacy practices, which is a different document with prescribed content and its own distribution rules. Nothing in the Privacy Rule asks a practice to publish a compliance standing, and any vendor implying otherwise is inventing an obligation.
What can we point patients at now?
A governed channel rather than an email address: practices on Basic can invite a patient into Secure Messaging and exchange with them there. It is less of a statement than a public page, and it is a real one.

In development, and the least decided of the things we are building.

The problem is real and the answer is not obvious. What a practice can do today is handle the patient relationship in a governed channel rather than an inbox, which is live in Basic.