How the connection to your practice software works
Practice Evolved reads your practice management system and never writes to it. The connection runs from a small program on a computer inside your office, outward to us. We never connect inward to your network, and your database credentials never leave your building.
The four things owners ask first
No. Every query the agent sends is checked before it is sent, and anything that is not a read is refused. This is enforced in the code rather than by policy, and it is the constraint the whole product is built inside.
No. Credentials stay on the office computer that runs the sync program. They are never sent to us, never stored in our systems, and never appear in a log.
No. The connection is outbound only. The program in your office sends us what it read; nothing of ours dials in, so there is no port to open and no inbound rule to add.
Yes. Where we handle protected health information on a practice's behalf we act as a business associate under a written agreement with that practice, and the agreement governs.
What we read
The financial and operational side of your practice: insurance claims and their status, adjustments, accounts receivable balances, appointments and recall, provider production, and the reference data that makes those meaningful, such as your insurers and fee schedules.
So your own staff can work that data, a limited set of patient identifiers travels with an open claim: a name, and where it is needed to talk to a payer about that claim, a date of birth and a member number. Those reach your authenticated dashboard and nowhere else. They are never written to a log, an email or an export.
What we never read
Clinical charting beyond what a claim carries, imaging, Social Security numbers, and patient contact details such as home addresses and telephone numbers. We do not use practice data for advertising and we do not sell it.
The one thing that can be written back, and only if you turn it on
There is exactly one exception to read only, it is off unless a practice enables it, and it covers notes and nothing else. When your team writes a note in the dashboard, it can be posted back into the patient's record so the practice software stays the single record of what happened. Nothing else is ever written: not a balance, not a claim status, not a payment, not a derived figure. The write path is separate from every read path and cannot be reached from one.
Questions we have not answered here
Real ones get a real answer from a person. The full legal detail is in the privacy policy, and anything it does not cover you can ask us directly.