Understand how Dermi Atlas Professional's self-hosted architecture and security features support your practice's compliance with HIPAA and PIPEDA.
Dermi Atlas Professional is designed with data sovereignty as a foundational principle. Unlike cloud-based imaging systems where data is stored by a third party, Dermi Atlas Professional uses a self-hosted architecture. This ensures that sensitive patient data, including clinical photographs, medical notes, and personal information, remains entirely within your control on your own infrastructure.
This article provides an overview of how Dermi Atlas Professional acts as a tool to support your practice's compliance with healthcare privacy regulations, including HIPAA (United States) and PIPEDA (Canada).
The core of Dermi’s security model is local data custody. Because the software runs on your local network, Dermi Inc. does not have access to, nor does it store, your patient health information.
Data Stored Locally (Your Responsibility):
Data Processed by Dermi (Vendor Responsibility):
This separation ensures that Dermi does not function as a "Business Associate" (under HIPAA) or a "Health Information Custodian" (under Canadian law) regarding your patient data. Your practice retains full ownership and control.
Dermi Atlas Professional provides technical features that allow practices to implement required administrative, technical, and physical safeguards.
Your feedback helps us improve our documentation
Contact our support team for personalized help
While Dermi provides the software tools, compliance is a shared responsibility.
Dermi's Responsibility:
Your Practice's Responsibility:
Dermi Atlas Professional is a software tool that facilitates compliance; it does not ensure compliance by itself. Compliance depends on how your practice configures the software, secures the host environment, and enforces organizational policies. Dermi Inc. does not provide legal advice. Please consult with your compliance officer or legal counsel to ensure your deployment meets all applicable regulatory requirements.