Security & Compliance
Fill The Hour is built with healthcare data security as a core principle, not an afterthought.
Privacy & Data Protection
We design Fill The Hour around healthcare privacy principles and apply the minimum-necessary standard to all data access.
- Minimum-necessary standard applied to all data access
- Row-level security isolating each practice's data
- No session recording or screen capture — our error monitoring never sees what is on your screen, and client names and phone numbers are stripped from error reports before they leave our servers
- Soft-delete audit trail rather than hard deletion
- Working toward Business Associate Agreements (BAAs) with our data processors as we scale
Data Encryption
All data is encrypted both at rest and in transit using industry-standard protocols.
- AES-256 encryption at rest for all stored data
- TLS 1.3 encryption for all data in transit
- OAuth tokens encrypted and stored separately from user data
- Database connections encrypted end-to-end
Access Control
Strict access controls ensure that only authorized users can view patient data.
- Row-Level Security (RLS) on all database tables
- Each therapist can only access their own client data
- Server-side authentication on every API request
- Email verification required before account access
SMS Compliance (TCPA)
Our SMS features are built to comply with the Telephone Consumer Protection Act.
- Every message template includes opt-out instructions, and the composer warns you before sending copy that drops them
- STOP keyword immediately halts all messages to that number
- Opt-out status tracked and enforced at the platform level
- Practitioners must confirm client consent before sending
Calendar Integration Security
Calendar connections use OAuth 2.0, scoped to what filling a slot actually requires.
- We read your calendar to spot cancellations, and write back only the appointment a client just claimed
- We never edit or delete bookings we did not create
- Only appointment titles and times are read, not notes or attachments
- OAuth tokens refreshed automatically, stored encrypted
- Disconnect anytime — we delete our copy of your tokens immediately, and you can revoke our access from your Google account at any time
Have security questions or need compliance documentation?
support@fill-the-hour.com