Security and privacy
Hospital ATS holds recruiting records: positions, candidates, offers and credentialing status. It doesn’t hold patient records. Here is how we protect what it does hold.
Each hospital’s data stays with that hospital
- The database enforces the separation. Every record belongs to one hospital, and the database refuses to show it to anyone outside that hospital, whatever screen or request asks for it.
- We test this with every release: one hospital’s staff try to read and change another hospital’s records, and the tests fail if any attempt succeeds.
Signing in
- Two-step sign-in is required for System Admins. Each hospital decides whether everyone else needs it too.
- People are signed out after 30 minutes without activity.
- Accounts are created by your System Admin; nobody can sign themselves up.
- Roles decide what each person can see and do: System Admin, recruiting, credentialing, department director, administration, accounting and view-only. Only System Admins and accounting see bills.
Knowing who did what
- An activity log records who viewed or changed provider records, and when. System Admins can review it.
- A credentialing file locks when a provider is hired. Only a System Admin can unlock it, and the unlock is recorded.
Less to protect
- No credentialing documents are stored: the checklist keeps status and dates, and the documents stay in your own credentialing systems.
- No visa details: only whether a provider needs sponsorship.
- Resumes/CVs sent through your careers page are deleted after 90 days if nobody adds the applicant.
- Your hospital can download a copy of its data.
Your careers page
- Applications pass spam checks before they reach you, and uploaded files are checked to be real PDF or Word documents.
- Only what you choose to publish is public. Internal notes, budgets and reasons for an opening never appear.
AI features
- AI features are optional. Your System Admin can turn each one off, and sets how many AI actions each person may use.
- AI requests go through our servers; no AI keys are stored in browsers.
How it’s built
- Everything travels over HTTPS, and data is encrypted at rest by our database host.
- The app sends strict browser security headers and loads no ads, trackers or third-party analytics. Its fonts and code are served from our own site.
Questions from your security, privacy or compliance team, including about HIPAA? Email hello@herricktechsystems.com and we’ll answer them in writing.