Security and privacy

Hospital ATS holds recruiting records: positions, candidates, offers and credentialing status. It doesn’t hold patient records. Here is how we protect what it does hold.

Each hospital’s data stays with that hospital

  • The database enforces the separation. Every record belongs to one hospital, and the database refuses to show it to anyone outside that hospital, whatever screen or request asks for it.
  • We test this with every release: one hospital’s staff try to read and change another hospital’s records, and the tests fail if any attempt succeeds.

Signing in

  • Two-step sign-in is required for System Admins. Each hospital decides whether everyone else needs it too.
  • People are signed out after 30 minutes without activity.
  • Accounts are created by your System Admin; nobody can sign themselves up.
  • Roles decide what each person can see and do: System Admin, recruiting, credentialing, department director, administration, accounting and view-only. Only System Admins and accounting see bills.

Knowing who did what

  • An activity log records who viewed or changed provider records, and when. System Admins can review it.
  • A credentialing file locks when a provider is hired. Only a System Admin can unlock it, and the unlock is recorded.

Less to protect

  • No credentialing documents are stored: the checklist keeps status and dates, and the documents stay in your own credentialing systems.
  • No visa details: only whether a provider needs sponsorship.
  • Resumes/CVs sent through your careers page are deleted after 90 days if nobody adds the applicant.
  • Your hospital can download a copy of its data.

Your careers page

  • Applications pass spam checks before they reach you, and uploaded files are checked to be real PDF or Word documents.
  • Only what you choose to publish is public. Internal notes, budgets and reasons for an opening never appear.

AI features

  • AI features are optional. Your System Admin can turn each one off, and sets how many AI actions each person may use.
  • AI requests go through our servers; no AI keys are stored in browsers.

How it’s built

  • Everything travels over HTTPS, and data is encrypted at rest by our database host.
  • The app sends strict browser security headers and loads no ads, trackers or third-party analytics. Its fonts and code are served from our own site.
Questions from your security, privacy or compliance team, including about HIPAA? Email hello@herricktechsystems.com and we’ll answer them in writing.