Dermi
Compliance-Ready Architecture

Compliance-ready architecture
for healthcare imaging

On-premises deployment keeps patient data under your direct organizational control. TLS encryption, configurable audit logging, and data retention tools support HIPAA, PIPEDA, and Australian Privacy Act regulatory requirements.

  • 01HIPAA ReadyArchitecture aligned with HIPAA requirements
  • 02PIPEDA ReadySupports Canadian privacy legislation
  • 03Privacy Act ReadySupports the Australian Privacy Act and APPs
  • 04Full TLS EncryptionHTTPS and WSS secured connections
In the product

Compliance tools in the interface

See how audit logging, data retention, and activity tracking are configured in Dermi Atlas.

Audit logging configuration

Configure logging levels from essential authentication events to comprehensive system interaction tracking.

Data retention policy

Set retention periods for deleted records and associated audit logs before permanent removal.

Activity log tracking

Track user actions with timestamped entries categorized by type for auditing, compliance, and operational visibility.

See how compliance features work in practice

Explore the full Dermi Atlas platform to see audit logging, encryption, and data retention controls in action.

Benefits

Compliance capabilities in detail

Select a category to explore specific compliance-supporting features

Encryption and access control

All network traffic within your Atlas deployment is encrypted using TLS. Every team member has a named account that supports two-factor authentication, session management, and single-use verification links for account operations.

Key features
TLS Encryption
HTTPS and WSS with self-signed certificates via Atlas Manager
Two-Factor Authentication
Optional 2FA per named account, with authenticator app support and recovery codes
Session Management
Secure session handling with configurable policies
Network Isolation
Local network access keeps the deployment unreachable from the public internet

Security built into the foundation. Every architectural decision in Dermi Atlas prioritizes patient privacy, data security, and regulatory alignment.

Questions

Common questions about compliance

How Dermi Atlas architecture supports HIPAA, PIPEDA, and Australian Privacy Act requirements

On-premises deployment places every step of data handling within your organizational boundary. Patient data never traverses external infrastructure, audit logging tracks all access and modifications, TLS encryption secures network traffic, and configurable retention policies support your compliance obligations.

The on-premises architecture supports PIPEDA requirements by keeping personal health information under the direct control of the collecting organization. Data residency, access logging, consent management, and data portability features align with PIPEDA principles for handling personal information.

The on-premises architecture supports obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) by keeping health information under the direct control of the practice. Local data residency, configurable audit logging, consent management, and data portability features help practices act as custodians of patient health information in line with the APPs and applicable state and territory health records legislation. The Dermi privacy policy and sub-processors document also identify cross-border destinations in line with APP 8.1 transparency requirements.

Two logging levels are configurable through Atlas Manager. Essential logging tracks authentication events such as logins and session activity. Comprehensive logging captures all user interactions including data access, modifications, exports, and consent actions, with user, timestamp, and operation details; authentication events and report exports additionally record the device.

Atlas supports three configurable deletion policies. Recoverable mode retains deleted data for a defined period before permanent removal. Standard mode removes data after a retention period. Permanent mode deletes immediately. All deletion actions require explicit confirmation and are logged.

Dermi Atlas provides compliance-ready architecture designed to support practices in meeting HIPAA, PIPEDA, and Australian Privacy Act requirements. The on-premises model means the practice maintains direct control over compliance implementation. Users are responsible for ensuring their deployment meets all applicable regulatory requirements for their jurisdiction, including any state or territory health records legislation.

Need compliance guidance?

Review our security documentation or contact our team for questions about compliance capabilities.

Explore compliance-ready clinical imaging

Learn how Dermi Atlas combines on-premises deployment, encryption, audit logging, and data retention tools to support healthcare compliance.

11Get started

Try Dermi Atlas today

Start with Dermi Atlas Cloud for free, or run Dermi Atlas Professional in your practice from $79 USD per month with a Clinician and an Assistant account included, first 30 days free.

Try First
Free Access

Dermi Atlas Cloud Demo

Free
  • No time limit

Explore Dermi Atlas features in your browser with our hosted demo environment, signed in with a free Dermi account. Free forever, no commitment required.

  • Runs in the browser with a free Dermi account
  • Upload and test with your own sample data
  • Access core features and workflows
  • No credit card required
  • Not for real patient data
  • Data may be cleared periodically
Full Installation

Dermi Atlas Professional

from$79 USD/month
  • Base plan per deployment
  • First 30 days free
  • Cancel anytime
One Clinician and one Assistant account included
  • Additional clinician seat$59 USD / month
  • Additional assistant seat$12 USD / month

Runs on the computers your practice already has, with complete feature access, real patient data support, and dedicated technical support. Photos stay in your practice.

  • No new hardware: runs on your existing server or workstation
  • Use with real patient data securely
  • One shared patient record for the team, with a login for every person
  • Setup done for you at no charge, with technical support included
No credit card for demo
Self-service setup via Atlas Manager
Assisted setup included, free
You own your photos
Runs on computers you already own
Accepted payment methods:
AMEXDISCOVER

Need help choosing?

Learn more about Atlas Professional features, explore Atlas Manager for deployment and infrastructure management, or speak with our team about your practice needs

Purpose-built for med spas, aesthetic clinics, plastic surgery, and dermatology practices · HIPAA, PIPEDA & Australian Privacy Act compliance-ready architecture · Complete data sovereignty

Synthetic Data Notice

All demonstrations, screenshots, and media on this page use synthetic data only. No real patient information is shown.

The following are synthetic and do not correspond to real patients:

  • All human faces and individuals are synthetic and do not represent real people
  • All clinical and medical images, including photographs and scans, are synthetic or simulated
  • All patient names, dates, identifiers, and other details are fictional
  • All clinical notes and documentation are sample content for demonstration only

Media is provided solely to illustrate platform functionality and workflows.