Security at ADMTD

ADMTD handles sensitive admissions data, so security and privacy are designed into the platform, not added later.

Built for HIPAA-conscious and 42 CFR Part 2 workflows. This page describes the security practices of the ADMTD application used by treatment providers. We sign a Business Associate Agreement (BAA) before any protected health information (PHI) is shared. Our public marketing site is kept operationally separate and does not process PHI.

Access & identity

Unique logins & role-based access

Every user has their own account, and role-based access controls limit each person to the data and actions their role requires.

Multi-factor authentication

MFA adds a second factor at sign-in, and automatic sign-out ends idle sessions to reduce the risk of unauthorized access.

Per-facility data isolation

Each facility's data is separated. Multi-site teams see only their own locations, while leadership can be granted an organization-wide view.

Audit trail

Key actions are recorded in an audit log that captures who did what and when, supporting accountability and review.

Data protection

Encryption

Data is encrypted in transit using industry-standard TLS, and stored data is encrypted at rest.

Trusted infrastructure

ADMTD runs on reputable cloud infrastructure with network controls and regular backups to support availability and recovery.

Least-privilege operations

Administrative access is limited to the minimum necessary and reviewed periodically.

Marketing site separation

This website and its analytics are kept separate from the application. No patient information is collected or processed here.

AI, used responsibly

AI features in ADMTD are optional and assistive. They draft summaries and help fill fields for a person to review, they do not take actions on their own, and no patient data is used to train any AI model. Facilities can run the entire platform with AI turned off.

Compliance

ADMTD is built to support the technical safeguards that HIPAA and 42 CFR Part 2 expect, including access controls, encryption, and audit logging. We sign a BAA with covered entities. ADMTD is not an electronic health record and does not provide clinical or coverage determinations.

Reporting a vulnerability

If you believe you have found a security issue, we want to hear from you. Please email security@admtd.ai with details, and avoid publicly disclosing the issue until we have had a chance to investigate and respond.

Contact

Questions about security or a BAA? Contact security@admtd.ai.

This page describes current practices at a high level and is provided for general information. It is not a warranty or a contract. Specific security commitments are set out in your agreement and BAA with ADMTD. Please have security and compliance language reviewed by qualified counsel before relying on it.