System Access and Security
User provisioning, credential handling, and security controls
- Version 1.0
- Effective date:
- August 10, 2026
- Last updated:
- August 10, 2026
1. Named User Accounts
Each account is provisioned with three individually named user accounts: Primary MVA, Team Lead, and Backup MVA.
Shared or generic logins are prohibited because they defeat session attribution, monitoring, and investigation. Permissions are granted on a minimum necessary basis.
2. Credential Transmission
Credentials are transmitted using two separate channels:
- usernames and login URLs by secure email, with no passwords included;
- passwords by text to our secure line at 813-591-5661, referencing the system but not repeating the username.
All credentials are stored in an encrypted password vault and shared only with named personnel assigned to the account. Vault access is revoked immediately when a team member leaves the account. The client remains responsible for disabling accounts in systems it controls.
Where a client's systems support direct secure credential sharing, single sign-on, or delegated provisioning, we use that method in preference.
3. Security Controls
- continuous endpoint monitoring and data loss detection;
- private VPN on dedicated IP addresses that clients may allowlist;
- multi-factor authentication where supported;
- unique strong passwords per system, rotated not less than every thirty days;
- biometric identity verification at session start;
- geographic access restriction to approved work locations, with blocking and alerting on attempts from outside them;
- camera-on presence for the duration of each clocked shift, with Team Lead check-ins;
- documented HIPAA training before access is granted and refreshed at least annually;
- private monitored workspaces verified at onboarding and on an ongoing basis.
4. Optional Live Workspace Streaming
An optional additional subscription allows a client to view the assigned team member's workspace in real time during working hours. The controls in Section 3 apply whether or not this option is elected.
5. Client Responsibilities
- create named accounts with minimum necessary permissions;
- transmit credentials using the two-channel method described above;
- notify us the same day of any change to systems, permissions, or personnel;
- notify us immediately of suspected credential exposure so that access can be disabled before investigation;
- confirm whether any payer agreement, government program, or state law restricts access to patient data by personnel located outside the United States.