Trust & security

Security you can see in the product

Dolce is built with HIPAA safeguards. Each one below is a real setting or screen your team uses every day.

Dolce Health · Admin · Security
SecurityProtected
Session timeoutSign out after inactivity
30 minutes
Lock screenPIN or password, switch user on shared iPads
Two-factor sign-inAuthenticator app code at login
IP allowlistOffice Network · 203.0.113.0/24
Add
Audit log retentionEvery sign, amend, view and refund
7 years

Sign & lock

When a provider signs, the note locks. It can’t be edited after that, only amended.

Amendments with a reason

Every amendment records who changed what, when, and why.

Medical director co-sign

Notes can go to a review queue where the medical director approves or requests changes.

Audit trail

Signs, amendments, deletions, refunds and record views are logged. Retention defaults to seven years.

Roles & permissions

Custom roles decide who can chart, sign, co-sign, refund, run campaigns or change settings.

One login per person

Every action is attributed to the person who took it, so the audit trail means something.

Session timeout

Idle sessions end automatically. The default is 30 minutes.

Lock screen & switch user

Lock a shared iPad with a PIN or password and switch users without signing out.

IP allowlist

Limit sign-in to networks you trust, like your office.

Two-factor sign-in

Add a code from an authenticator app at sign-in.

E-signature evidence

Typed signatures log the time, IP address and device.

Consent-aware messaging

Signed unsubscribe links and suppression are honored at send time.

Audit trail

Every sign, amend, view and refund, on the record

Filter by person or action. Amendments show their reason. Retention defaults to seven years.

Dolce Health · Admin · Audit log
Audit trailFilter
10:42 AMJenna P.Signed note #2231
10:44 AMDr. RaoCo-signed note #2231
11:02 AMDana R.Amended note #2198 · reason: corrected lot
11:15 AMFront deskViewed patient record · Maya R.
11:31 AMDana R.Issued refund INV-1036
Access

People see what their job needs

Build roles for owners, medical directors, injectors and the front desk. Invite by link, and deactivate someone in one click when they leave.

Team & permissions
Dolce Health · Admin · Team
Roles & permissionsNew role
OwnerMedical directorInjectorFront desk
View charts
Sign notes
Co-sign as MD
Take payments
Issue refunds
Run campaigns
Admin settings
Shared responsibility

What your practice controls

Security is a partnership. These parts are in your hands, and Dolce gives you the tools for each one.

  • Clinical decisions. Your providers own treatment decisions and every signed note.
  • Who gets access. You decide who is invited, which role they get and when they’re removed.
  • Patient consent. You choose which forms each service requires and what patients sign.
  • Marketing consent. You decide who receives campaigns. Dolce honors unsubscribes and suppression.
FAQ

Security questions

Can’t find what you need? Ask us on a demo call.

Ask on a demo
Is Dolce HIPAA compliant?
Compliance depends on how a practice uses any system, so we describe what’s built: sign and lock, reason-required amendments, an audit trail, roles, session timeout, lock screen, IP allowlist and two-factor sign-in. Ask us for our security documentation on a call.
Will you sign a BAA?
Talk to us about your BAA requirements on a demo or at security@dolcehealthemr.com.
Where do card numbers go?
Card processing through Authorize.Net is rolling out. Card numbers are tokenized in the browser and never touch Dolce’s servers.
Does the AI see patient data?
AI features send the text they need to draft a note, summary or message. The result is a draft that a person reviews. Nothing is signed or sent by the AI.
Can we export our data?
Yes. Patient data exports as CSV at any time.

Bring your security questions

We’ll walk through each control in the product, live.