Compliance-ready imagingFor HIPAA, PIPEDA, and Australian privacy law.
Accounts, encryption, updates, and backups
Audit logging and retention
Audit logging configuration
Essential records sign-ins and account changes; Comprehensive records every page access and data change.
Data retention policy
The retention period sets how long deleted records, files, and their logs are kept.
Patient activity logs
Each patient's activity log lists actions by member and time, filtered by action, resource, and period.
Compliance capabilities in detail
Encryption and access
Sensitive account changes are confirmed through a single-use link, emailed to the member or opened from Dermi Atlas Manager.
Audit trails and logging
Retention and deletion
Frequently asked questions
It keeps patient data handling inside the practice: records stay on its own computers, audit logging tracks access and changes, devices can connect over HTTPS, and retention settings support the practice's obligations.
The on-premises deployment is designed to support PIPEDA by keeping personal health information under the control of the collecting organization, with local data residency, access logging, consent records, and practice-controlled backups.
It is designed to support the Privacy Act 1988 (Cth) and the Australian Privacy Principles by keeping health information under the practice's control, with local residency, audit logging, and consent records. The Dermi privacy policy names cross-border destinations, in line with APP 1.4.
Two levels are set in Dermi Atlas Manager. Essential records sign-ins and account changes only; Comprehensive, the default, records every page access, record operation, and data change. Sign-ins and PDF report exports also record the device.
Three deletion policies are set in Dermi Atlas Manager. Recoverable keeps deleted records, files, and their activity logs for the retention period; Standard, the default, keeps the records and files but removes their logs; Permanent removes all of it immediately.
Dermi Atlas is compliance-ready and designed to support HIPAA, PIPEDA, and the Australian Privacy Act, and the practice keeps direct control of its deployment. Each practice remains responsible for meeting the requirements of its jurisdiction, including state and territory health records laws.
Try the compliance controls in Dermi Atlas
The demo runs in a browser; the free trial runs on the computers your practice already owns.
Resources and further reading
Related pages
Plans, pricing, and free trial
Atlas Cloud Demo
- No time limit
- No credit card
- Nearly every feature, with photos you upload
- Runs in a browser, nothing to install
- A free Dermi Cloud Services account to sign in
- Not for real patient data
- Data cleared at least weekly
Dermi Atlas Professional
- Base plan per deployment
- First 30 days free
- Additional clinician seat$59 USD / month
- Additional assistant seat$12 USD / month
- Every feature, with real patient records
- Runs on computers the practice already owns
- Technical support at no extra charge
Synthetic Data Notice
All demonstrations, screenshots, and media on this page use synthetic data only. No real patient information is shown.
The following are synthetic and do not correspond to real patients:
- All human faces and individuals are synthetic and do not represent real people
- All clinical and medical images, including photographs and scans, are synthetic or simulated
- All patient names, dates, identifiers, and other details are fictional
- All clinical notes and documentation are sample content for demonstration only
Media is provided solely to illustrate platform functionality and workflows.