Security & Compliance

Fill The Hour is built with healthcare data security as a core principle, not an afterthought.

Privacy & Data Protection

We design Fill The Hour around healthcare privacy principles and apply the minimum-necessary standard to all data access.

  • Minimum-necessary standard applied to all data access
  • Row-level security isolating each practice's data
  • No session recording or screen capture — our error monitoring never sees what is on your screen, and client names and phone numbers are stripped from error reports before they leave our servers
  • Soft-delete audit trail rather than hard deletion
  • Working toward Business Associate Agreements (BAAs) with our data processors as we scale

Data Encryption

All data is encrypted both at rest and in transit using industry-standard protocols.

  • AES-256 encryption at rest for all stored data
  • TLS 1.3 encryption for all data in transit
  • OAuth tokens encrypted and stored separately from user data
  • Database connections encrypted end-to-end

Access Control

Strict access controls ensure that only authorized users can view patient data.

  • Row-Level Security (RLS) on all database tables
  • Each therapist can only access their own client data
  • Server-side authentication on every API request
  • Email verification required before account access

SMS Compliance (TCPA)

Our SMS features are built to comply with the Telephone Consumer Protection Act.

  • Every message template includes opt-out instructions, and the composer warns you before sending copy that drops them
  • STOP keyword immediately halts all messages to that number
  • Opt-out status tracked and enforced at the platform level
  • Practitioners must confirm client consent before sending

Calendar Integration Security

Calendar connections use OAuth 2.0, scoped to what filling a slot actually requires.

  • We read your calendar to spot cancellations, and write back only the appointment a client just claimed
  • We never edit or delete bookings we did not create
  • Only appointment titles and times are read, not notes or attachments
  • OAuth tokens refreshed automatically, stored encrypted
  • Disconnect anytime — we delete our copy of your tokens immediately, and you can revoke our access from your Google account at any time

Have security questions or need compliance documentation?

support@fill-the-hour.com