Skip to main content

Instinct Security Overview

Written by Meridythe Lanoue

Your team should be able to focus on patients, not on whether your data is safe. Security for Instinct EMR and Treatment Plan are built into how we run, not bolted on afterward.

This article covers how we protect your practice's information, what our SOC 2 Type II certification means, and how to request security documentation for an IT review.

Who at Instinct can access your data?

Only the people whose job requires it. We use role-based access and least privilege, so an Instinct employee gets access to what their role needs and nothing beyond it.

How does Instinct secure employee logins?

Every Instinct employee must use a strong password and multi-factor authentication (MFA) to reach any system that touches customer data. This is enforced, not optional.

How is the network protected?

Firewalls protect all public-facing endpoints.

Is your data encrypted?

Yes, in both directions. Transactions are encrypted end to end, and all data is encrypted at rest.

How does Instinct find problems before customers do?

We run real-time vulnerability scanning at every stage, from development through production. Issues get caught before they reach your practice.

What happens when something breaks at 2 AM?

A dedicated team monitors our systems 24/7. Critical incidents route to that team with escalation support behind them.

What does SOC 2 Type II certification mean?

It means an independent auditor reviewed our security controls over a period of time, not at a single point. The audit covers five areas: security, availability, processing integrity, confidentiality, and privacy.

Type II is the more rigorous level. A Type I audit checks whether the controls exist. Type II checks whether they actually held up over months of real operation.

What security training do Instinct employees complete?

All employees complete security training annually.

How do you request a copy of our SOC 2 report?

Security is a shared responsibility, and we are committed to ongoing investments to keep our customers’ data safe. 🧡

If you have any questions, please email us at [email protected].

Did this answer your question?