Security & Compliance
Security and HIPAA-compliant safeguards for sober living software
Recovery residences handle sensitive resident, billing, document, and communication data.
Oathtrack is designed to help teams centralize that information securely, limit access by staff role,
and support privacy-conscious operating practices.
Encrypted Data
Encryption for sensitive data in transit and at rest.
Role-Based Access
Permissions help staff access only what their role requires.
Secure Hosting
AWS infrastructure with HIPAA-eligible services for protected data workflows.
Backups
Encrypted backups and snapshots help protect against data loss.
How Oathtrack Protects Your Data
Security works best when infrastructure, product design, operational process, and customer practices
all support the same goal: protecting resident information without slowing your team down.
Data Protection
Oathtrack helps recovery residence teams store resident records, documents, billing data,
notes, tasks, and communications in one controlled system.
- Encrypted connections for data transmitted between users and the platform.
- Encrypted storage for sensitive platform data and backups.
- Centralized records to reduce scattered files, spreadsheets, and unmanaged copies.
- Secure file storage and document e-signature workflows for resident documentation.
Access Controls
Each user should have their own account, and access should match their responsibilities.
Oathtrack supports that workflow with role-based permissions.
- User-specific login credentials for staff accounts.
- Staff roles and permissions for limiting access by responsibility.
- Account access can be removed when staff leave or change roles.
- Resident portal access is separate from staff dashboard access.
Secure Infrastructure
Oathtrack uses Amazon Web Services
infrastructure and HIPAA-eligible services where electronic protected health information may be stored,
processed, or transmitted.
- Encrypted disk volumes and database backups.
- Fault-tolerant storage and highly durable backup storage.
- Nightly snapshots for recovery support.
- Network controls, firewall review, and restricted administrative access practices.
Monitoring & Maintenance
Security is an ongoing practice, not a one-time setting. Oathtrack maintains operational routines
that support detection, review, and remediation.
- Review of published vulnerabilities and exposures.
- Security patching and platform maintenance routines.
- Firewall and access rule review.
- Monitoring for suspicious access patterns and system issues.
Technical Security Specs
Oathtrack security is built around three parts of a secure cloud software platform:
computing infrastructure, application design, and operational best practices.
Industry Standards and Best Practices
- Oathtrack follows security practices informed by National Institute of Standards and Technology (NIST) and Federal Information Processing Standard (FIPS) recommendations.
- Data at rest is encrypted using AES encryption with 256-bit keys.
- Oathtrack uses RSA, DSA, and ECC encryption algorithms within the same SSL certificate.
- SSL security certificates are refreshed frequently.
- Vulnerability assessment and website malware scanning help protect the platform from malicious activity.
- Transmitted data and PHI are encrypted using strong TLS 1.2 or higher.
- TLS connections use AES_256_CBC, SHA256 with RSA 2048 bits for message authentication, and ECDHE_RSA as the key exchange mechanism.
- SSH access to application environments is configured according to Center for Internet Security (CIS) benchmark recommendations.
- Network traffic can be restricted to specific whitelisted IP addresses or VPN connections on a per-environment basis.
- Intrusion attempts are automatically identified and blocked by IP address for a significant duration, helping mitigate SSH dictionary attacks and other malicious behavior.
Data Storage Built for Peace of Mind
- Oathtrack is hosted on HIPAA compliant cloud infrastructure from Amazon Web Services.
- Data stored in Oathtrack is designed to be recoverable, helping protect customers against accidental loss or mistakes.
- Database backups are encrypted and stored in highly durable storage infrastructure with 99.999999999% durability and 99.99% availability.
- Disk volumes use fault-tolerant, high-availability storage.
- Nightly snapshots create a backup of each disk volume.
- Database backups are automatically enabled based on a consistent schedule, sensible rotation, and retention policy.
Authentication, Access Control, and Authorization
- Each secure Oathtrack site requires a unique username and password combination for account access.
- Oathtrack user profiles and associated resident charts are protected behind authenticated access.
- Customers are responsible for protecting usernames, passwords, and staff access practices.
Platform Ops Security and Compliance Routines
- Analysis of intrusion detection system data for anomalous activity and system issues.
- Audits of firewall rules and IP address whitelists.
- Review of published vulnerabilities and exposures.
- Security patching and platform maintenance.
Best Practices
- HIPAA compliance requires internal best practices to be established and maintained by each organization.
- Oathtrack helps support those practices by centralizing operational, resident, document, billing, and staff information in one controlled platform.
User Roles and Permissions
- Access control is managed through Oathtrack user roles.
- Each employee is assigned a user role when they are added to the system.
- Permissions govern what users can access based on their assigned role.
HIPAA and Shared Responsibility
Oathtrack is HIPAA compliant and built to support HIPAA-conscious workflows, but HIPAA compliance is shared.
Your organization is responsible for using the platform appropriately, training staff, assigning
least-privilege access, maintaining internal policies, and following privacy and breach-response obligations
that apply to your program. For more background, review the
HHS HIPAA Security Rule summary.
Designed Around Recovery Residence Operations
Oathtrack security is tied to the work your team does every day: resident charts, payments, drug test records,
documents, notes, calendars, chores, passes, forms, and staff communication. The goal is to keep sensitive
information organized in one platform while giving operators practical control over who can see and do what.
Security FAQ
Quick answers for operators evaluating sober living and recovery residence management software.
Is Oathtrack HIPAA compliant?
Oathtrack is HIPAA compliant and designed to support HIPAA-conscious operations through administrative, technical, and physical safeguards. HIPAA compliance also depends on each customer using the platform appropriately, managing user access, training staff, and maintaining required internal policies.
Where is Oathtrack hosted?
Oathtrack uses Amazon Web Services infrastructure and HIPAA-eligible services where electronic protected health information may be stored, processed, or transmitted.
Is Oathtrack data encrypted?
Oathtrack uses encrypted connections for data in transit and encrypted storage for sensitive platform data and backups.
Can staff access be limited by role?
Yes. Oathtrack includes role-based permissions so organizations can limit staff access based on job responsibilities and program needs.
How should I report a security concern?
Send security questions or concerns to security@oathtrack.com or contact Oathtrack support by phone at 484-925-1580.