Oathtrack security icon Security & Compliance

Security and HIPAA-compliant safeguards for sober living software

Recovery residences handle sensitive resident, billing, document, and communication data. Oathtrack is designed to help teams centralize that information securely, limit access by staff role, and support privacy-conscious operating practices.

Encrypted Data Encryption for sensitive data in transit and at rest.
Role-Based Access Permissions help staff access only what their role requires.
Secure Hosting AWS infrastructure with HIPAA-eligible services for protected data workflows.
Backups Encrypted backups and snapshots help protect against data loss.

How Oathtrack Protects Your Data

Security works best when infrastructure, product design, operational process, and customer practices all support the same goal: protecting resident information without slowing your team down.

Data Protection

Oathtrack helps recovery residence teams store resident records, documents, billing data, notes, tasks, and communications in one controlled system.

  • Encrypted connections for data transmitted between users and the platform.
  • Encrypted storage for sensitive platform data and backups.
  • Centralized records to reduce scattered files, spreadsheets, and unmanaged copies.
  • Secure file storage and document e-signature workflows for resident documentation.

Access Controls

Each user should have their own account, and access should match their responsibilities. Oathtrack supports that workflow with role-based permissions.

  • User-specific login credentials for staff accounts.
  • Staff roles and permissions for limiting access by responsibility.
  • Account access can be removed when staff leave or change roles.
  • Resident portal access is separate from staff dashboard access.

Secure Infrastructure

Oathtrack uses Amazon Web Services infrastructure and HIPAA-eligible services where electronic protected health information may be stored, processed, or transmitted.

  • Encrypted disk volumes and database backups.
  • Fault-tolerant storage and highly durable backup storage.
  • Nightly snapshots for recovery support.
  • Network controls, firewall review, and restricted administrative access practices.

Monitoring & Maintenance

Security is an ongoing practice, not a one-time setting. Oathtrack maintains operational routines that support detection, review, and remediation.

  • Review of published vulnerabilities and exposures.
  • Security patching and platform maintenance routines.
  • Firewall and access rule review.
  • Monitoring for suspicious access patterns and system issues.

Technical Security Specs

Oathtrack security is built around three parts of a secure cloud software platform: computing infrastructure, application design, and operational best practices.

Industry Standards and Best Practices

  • Oathtrack follows security practices informed by National Institute of Standards and Technology (NIST) and Federal Information Processing Standard (FIPS) recommendations.
  • Data at rest is encrypted using AES encryption with 256-bit keys.
  • Oathtrack uses RSA, DSA, and ECC encryption algorithms within the same SSL certificate.
  • SSL security certificates are refreshed frequently.
  • Vulnerability assessment and website malware scanning help protect the platform from malicious activity.
  • Transmitted data and PHI are encrypted using strong TLS 1.2 or higher.
  • TLS connections use AES_256_CBC, SHA256 with RSA 2048 bits for message authentication, and ECDHE_RSA as the key exchange mechanism.
  • SSH access to application environments is configured according to Center for Internet Security (CIS) benchmark recommendations.
  • Network traffic can be restricted to specific whitelisted IP addresses or VPN connections on a per-environment basis.
  • Intrusion attempts are automatically identified and blocked by IP address for a significant duration, helping mitigate SSH dictionary attacks and other malicious behavior.

Data Storage Built for Peace of Mind

  • Oathtrack is hosted on HIPAA compliant cloud infrastructure from Amazon Web Services.
  • Data stored in Oathtrack is designed to be recoverable, helping protect customers against accidental loss or mistakes.
  • Database backups are encrypted and stored in highly durable storage infrastructure with 99.999999999% durability and 99.99% availability.
  • Disk volumes use fault-tolerant, high-availability storage.
  • Nightly snapshots create a backup of each disk volume.
  • Database backups are automatically enabled based on a consistent schedule, sensible rotation, and retention policy.

Authentication, Access Control, and Authorization

  • Each secure Oathtrack site requires a unique username and password combination for account access.
  • Oathtrack user profiles and associated resident charts are protected behind authenticated access.
  • Customers are responsible for protecting usernames, passwords, and staff access practices.

Platform Ops Security and Compliance Routines

  • Analysis of intrusion detection system data for anomalous activity and system issues.
  • Audits of firewall rules and IP address whitelists.
  • Review of published vulnerabilities and exposures.
  • Security patching and platform maintenance.

Best Practices

  • HIPAA compliance requires internal best practices to be established and maintained by each organization.
  • Oathtrack helps support those practices by centralizing operational, resident, document, billing, and staff information in one controlled platform.

User Roles and Permissions

  • Access control is managed through Oathtrack user roles.
  • Each employee is assigned a user role when they are added to the system.
  • Permissions govern what users can access based on their assigned role.

HIPAA and Shared Responsibility

Oathtrack is HIPAA compliant and built to support HIPAA-conscious workflows, but HIPAA compliance is shared. Your organization is responsible for using the platform appropriately, training staff, assigning least-privilege access, maintaining internal policies, and following privacy and breach-response obligations that apply to your program. For more background, review the HHS HIPAA Security Rule summary.

Designed Around Recovery Residence Operations

Oathtrack security is tied to the work your team does every day: resident charts, payments, drug test records, documents, notes, calendars, chores, passes, forms, and staff communication. The goal is to keep sensitive information organized in one platform while giving operators practical control over who can see and do what.

Security FAQ

Quick answers for operators evaluating sober living and recovery residence management software.

Is Oathtrack HIPAA compliant?

Oathtrack is HIPAA compliant and designed to support HIPAA-conscious operations through administrative, technical, and physical safeguards. HIPAA compliance also depends on each customer using the platform appropriately, managing user access, training staff, and maintaining required internal policies.

Where is Oathtrack hosted?

Oathtrack uses Amazon Web Services infrastructure and HIPAA-eligible services where electronic protected health information may be stored, processed, or transmitted.

Is Oathtrack data encrypted?

Oathtrack uses encrypted connections for data in transit and encrypted storage for sensitive platform data and backups.

Can staff access be limited by role?

Yes. Oathtrack includes role-based permissions so organizations can limit staff access based on job responsibilities and program needs.

How should I report a security concern?

Send security questions or concerns to security@oathtrack.com or contact Oathtrack support by phone at 484-925-1580.

Have a security or compliance question?

We are happy to talk through security, privacy, data handling, and implementation questions with your team.

security@oathtrack.com   |   (484) 925-1580