Dermi Atlas Professional is designed with data sovereignty as a foundational principle: an on-premises architecture that keeps sensitive patient data, including clinical photographs, medical notes, and personal information, entirely under the practice's control on its own infrastructure.
This article provides an overview of how Dermi Atlas Professional acts as a tool to support a practice's compliance with healthcare privacy regulations, including HIPAA (United States) and PIPEDA (Canada).
The On-Premises Model & Data Sovereignty
The core of Dermi's security model is local data custody. Because the software runs on the local network, Dermi Inc. does not have access to, nor does it store, patient health information.
Data Stored Locally (Practice Responsibility):
- Patient photographs and clinical images
- Patient demographic information and notes
- Audit logs and activity records
- User account data
- System backups
Data Processed by Dermi (Vendor Responsibility):
- License verification and subscription status
- Software update checks
- Account security metadata (e.g., 2FA or password reset initiation)
Because Dermi Atlas Professional is deployed on the practice's own infrastructure and stores patient data locally, Dermi Inc. does not access that data as part of normal operations, and the practice retains ownership and control of it. The full description of Dermi's role and the data Dermi processes is set out in the Dermi Privacy Policy, the Dermi Atlas Professional EULA, and the Dermi Sub-Processors document. Practices should consult their privacy officer or legal counsel for the resulting determination under HIPAA, PIPEDA, and applicable provincial or state law.
Compliance Support Features
Dermi Atlas Professional provides technical features that allow practices to implement required administrative, technical, and physical safeguards.
Access Control
- Individual Accounts: Each team member signs in under a named individual account, created only by claiming an invitation issued from Dermi Portal. Every action is recorded under the person who performed it.
- Account Types: Clinical records belong to the practice team and are available to every member of it. Access rights are drawn at the actions that carry legal weight: export, external sharing, deletion, recovery, patient merge, and identity edits are Clinician actions and are refused to Assistant accounts.
- Strong Authentication: Enforces password complexity and supports Two-Factor Authentication (2FA).
- Session Management: Lets users end all active sessions across devices in a single action.
Audit & Accountability
- Activity Logging: Configurable logging levels track authentication, data access, and modifications.
- Granular History: Logs record the timestamp, the acting account, the operation, the affected resource, and the before and after states where applicable. Authentication and account events additionally record IP address, user agent, and timezone.
- Local Storage: Audit logs are stored locally and included in the system backups.
Data Protection
- Encryption in Transit: Supports TLS encryption for network communications via self-signed certificates.
- Safe Deletion: Configurable deletion levels (Recoverable, Standard, and Permanent) let practices choose how deletions are handled. Recoverable and Standard retain deleted data and stored files for the configured retention period and support in-app recovery of patients, entries, and images (Recoverable also retains the associated activity logs; Standard removes them). Permanent immediately and permanently removes data with no recovery. All deletion operations require explicit confirmation.
- Deployment Isolation: Each deployment holds exactly one practice team, and its clinical records are reachable only by the members of that team signing in on that deployment. Membership is held in Dermi Portal as a name, an email address, and an account type; no clinical data is held in the cloud.
Consent Tools
- Workflow Integration: Configurable settings to prompt for consent before image capture.
- Documentation: Capabilities to record digital confirmation or verify external written consent.
Shared Responsibility Model
While Dermi provides the software tools, compliance is a shared responsibility.
Dermi's Responsibility:
- Maintain the software and publish updates, including security fixes, for delivery through Dermi Atlas Manager.
- Secure the administrative infrastructure (billing, licensing, account services).
Software is licensed under the Dermi Atlas Professional EULA.
Practice Responsibility:
- Physical Security: Securing the computer running Dermi Atlas Professional.
- Network Security: Configuring firewalls and securing the local network (Wi-Fi).
- Access Management: Inviting team members from Dermi Portal with the correct account type, reviewing that membership periodically, and removing a member when a staff member leaves.
- Backup Strategy: Regularly running backups and storing them securely off-site.
- Policy & Procedure: Establishing and enforcing internal privacy policies.
Related Documentation
- Data Security Architecture: Technical details on encryption and ports.
- Audit Logging Configuration: How to configure and view activity logs.
- Atlas Manager Administration: The admin passphrase, the account controls, and the deployment purge.
- Inviting and Managing Team Members: Adding, changing, and removing members from Dermi Portal.
- HIPAA Compliance Guide: Mapping features to US regulations.
- PIPEDA Compliance Guide: Mapping features to Canadian regulations.
- Configuring Data Retention for Deleted Records: Managing retention periods for compliance.
- Managing Patients for consent tracking and patient record management.
Disclaimer
Dermi Atlas Professional is a software tool that facilitates compliance; it does not ensure compliance by itself. Compliance depends on how the practice configures the software, secures the host environment, and enforces organizational policies. Dermi Inc. does not provide legal advice. Consult a compliance officer or legal counsel to ensure the deployment meets all applicable regulatory requirements.