Security built for healthcare workflows

TOM MMS is built with the safeguards ASCs and their patients expect.

HIPAA & Data Protection

  • Business Associate Agreement executed with each facility before any PHI is entered, and with infrastructure providers
  • PHI handled per HIPAA Privacy and Security Rule requirements
  • Encryption at rest, TLS 1.2+ in transit
  • PHI stored at rest in US database regions (the Supabase project region is set at creation and cannot be changed)
  • Row-level security: facilities cannot access each other's data
  • Role-based access: Owner, Admin, Pharmacist, PIC, Nurse, Auditor
  • PIN-based access for facility staff with brute-force rate limiting and session expiry

Drug Safety

  • Tall Man lettering on high-risk drug names (ISMP standard)
  • High-alert medication badges
  • Look-alike/sound-alike drug warnings
  • Dosing range alerts for high-quantity sign-outs
  • Real-time FDA shortage and recall monitoring

Audit & Activity History

  • Medication transactions, configuration changes, and pharmacist review actions recorded with user, timestamp, and event details
  • Timestamped activity history with user and event details
  • Pharmacist review window, on the facility's cadence
  • Branded PDF visit reports from structured visit data

Infrastructure & Reliability

  • Hosted on managed cloud infrastructure (Supabase + Vercel)
  • Database and file storage in US regions (Supabase)
  • Global edge network with automatic DDoS protection for site delivery
  • Automated error detection and alerting

Questions?

We're happy to discuss our security practices with your compliance team.

For assurance programs, subprocessors, BAA readiness, and reviewable documents, contact us to start a security review.

For what TOM MMS tracks in the medication room between pharmacist visits, see TOM for ASCs.

Made in Austin, TX