Security built for healthcare workflows
TOM MMS is built with the safeguards ASCs and their patients expect.
HIPAA & Data Protection
- Business Associate Agreement executed with each facility before any PHI is entered, and with infrastructure providers
- PHI handled per HIPAA Privacy and Security Rule requirements
- Encryption at rest, TLS 1.2+ in transit
- PHI stored at rest in US database regions (the Supabase project region is set at creation and cannot be changed)
- Row-level security: facilities cannot access each other's data
- Role-based access: Owner, Admin, Pharmacist, PIC, Nurse, Auditor
- PIN-based access for facility staff with brute-force rate limiting and session expiry
Drug Safety
- Tall Man lettering on high-risk drug names (ISMP standard)
- High-alert medication badges
- Look-alike/sound-alike drug warnings
- Dosing range alerts for high-quantity sign-outs
- Real-time FDA shortage and recall monitoring
Audit & Activity History
- Medication transactions, configuration changes, and pharmacist review actions recorded with user, timestamp, and event details
- Timestamped activity history with user and event details
- Pharmacist review window, on the facility's cadence
- Branded PDF visit reports from structured visit data
Infrastructure & Reliability
- Hosted on managed cloud infrastructure (Supabase + Vercel)
- Database and file storage in US regions (Supabase)
- Global edge network with automatic DDoS protection for site delivery
- Automated error detection and alerting
Questions?
We're happy to discuss our security practices with your compliance team.
For assurance programs, subprocessors, BAA readiness, and reviewable documents, contact us to start a security review.
For what TOM MMS tracks in the medication room between pharmacist visits, see TOM for ASCs.