Security and data handling
How DARO protects records, keeps them, and responds to incidents. Version 2026-09-26.
Access control
Every practice's data is separated at the database level. Staff access is by job role, with location limits in hospitals. Two-factor sign-in is required by default for clinical and billing roles. Idle screens lock with a PIN. Emergency access (break-glass) requires a reason and is reviewed. Every chart access is written to an audit log the practice can review.
Encryption
All traffic uses TLS. Data and files are encrypted at rest. Unlock PINs are stored only as salted one-way digests.
Backups and restore
The database is backed up daily with point-in-time recovery. Restores are rehearsed on a schedule and recorded. Target recovery: under 4 hours, with no more than 1 hour of data loss.
Records retention
Clinical records are kept for as long as the practice's subscription is active and for the period required by the practice's state after termination, unless the practice exports and requests deletion. Ambient audio is not retained by default. Device media follows the practice's retention setting. Audit logs are kept for at least six years.
Monitoring
Application errors are recorded and reviewed, and public endpoints are rate-limited to prevent abuse.
Incident and breach response
Suspected incidents are triaged within 24 hours. Affected practices are notified without unreasonable delay and no later than the BAA's deadline, with the facts needed for their own breach notification duties. Report a concern to security@daroclinical.com.
Downtime
If DARO is unavailable, the downtime mode and printed census and medication sheets let care continue. Entries made during downtime are reconciled into the record afterward.