Our approach to security

LicensureHelp is a small, focused team with years of credentialing experience. Our security architecture is designed from the ground up to protect provider data at any scale. The same infrastructure and controls described here apply whether we are serving one client or fifty.

We process and store provider data on our own infrastructure, and use carefully chosen outside services only where the work requires them. Our security practices are designed to be practical, honest, and appropriate for the sensitivity of the data we handle.

This page describes what we do, how we do it, and where we rely on trusted third parties for specific functions like email and e-signature.

On-premise infrastructure
Provider records are processed and stored on our own hardware; outside services used for the work carry only what each function needs. Off-site backups are always encrypted before leaving our servers.
Minimum necessary access
Every change to provider records goes through the application; nothing else can write to the database and files behind it. Each part of the system gets the minimum access its job requires.
Strong authentication
Company accounts use strong, unique credentials held in an end-to-end encrypted vault, one per service, never reused.
Full disk encryption
Every laptop and workstation used for client work is fully encrypted. If a device is lost or stolen, the data on it is inaccessible.

Where your data lives

Provider records, credentialing documents, and application data are stored on hardware we own and operate. This gives us direct control over where data lives and who can reach it.

Certain operational functions (such as email, e-signature, and encrypted off-site backups) involve trusted third-party providers. The categories are documented in the Third Parties section below. Any data that leaves our infrastructure is encrypted before transmission.

How we handle sensitive information

We are deliberate about which data enters our system and how it is stored. Provider records include contact information, licensure details, employment history, education, and credentialing documentation: the information necessary to complete licensing and credentialing work.

We collect the minimum needed for the work, and the most sensitive identifiers are handled outside our systems wherever the process allows.

Provider documents submitted to us, such as identification, licenses, and employment records, are stored securely on our own infrastructure and accessible only through authenticated access.

Who can access what

Provider data lives on our own server and is reachable only from company devices over a private, encrypted network. It is never exposed to the public internet. Work happens through the application, and the application server is the only component permitted to write to the underlying database and files: each part of the system gets the minimum access its job requires.

Data operations are recorded in an audit log: what was changed or exported, when, and from where. For every change, the log captures the state before and after, so any record can be reconstructed and any action accounted for.

Company accounts are protected with strong, unique credentials, one per service, never reused. They live in an end-to-end encrypted vault: its contents are encrypted before they ever leave our devices, so not even the vault provider can read them.

Device security standards

All devices used for client work are required to meet the following security standards before handling any provider data.

Full disk encryption — if a device is lost or stolen, data on it is inaccessible without the correct credentials.

Rapid revocation — access is tied to named devices and per-person credentials. A lost device or a departure is handled by revoking that identity centrally, and disk encryption keeps the data on the device unreadable in the meantime.

Security updates — all devices receive security updates promptly to protect against known vulnerabilities.

Password management — all accounts and services are managed through a password manager, with strong, unique passwords for every service.

Backup and recovery

We maintain multiple layers of backup to protect against data loss. All backups are encrypted before leaving our primary server. Backup encryption uses strong symmetric encryption with keys stored separately from the backup data itself.

Our backup strategy includes local snapshots for rapid recovery from software or hardware issues, and off-site encrypted backups for disaster recovery scenarios. In the event of a failure, service can be restored from encrypted backup.

Backup files are encrypted at rest and in transit regardless of where they are stored.

A note on HIPAA

HIPAA applies to covered entities and business associates that handle protected health information (PHI): patient medical records, diagnoses, treatment data, and similar. LicensureHelp handles provider credentialing data: licenses, employment history, education, and professional documentation. Our work neither needs nor asks for patient information, and HIPAA does not apply to credentialing services like ours.

If a document ever arrived with stray patient details in it, we would redact it before saving it to the provider's file, keep no unredacted copy, and let the sender know.

That said, we recognize that clients in healthcare expect a high standard of data protection regardless of regulatory scope. Our technical security controls (vault-managed credentials, full disk encryption, on-premise data processing, encrypted backups, and audit logging) are built in the spirit of protecting sensitive data to the same standard expected of organizations that do handle PHI.

Email and communications security

Business email is handled through an independent provider whose business model is subscriptions, not advertising. Mail is encrypted in transit.

Third-party services we use

We are transparent about where provider data touches outside services. These are the categories rather than an exhaustive registry of vendors; we name the specific services during contracting and on request, since a published vendor list mostly helps phishing attempts impersonate them.

Email and backup storage — business email and off-site backup storage run with an independent provider. Backups are encrypted on our own equipment before upload, so the storage provider only ever holds ciphertext it cannot read.

Credential vault — account credentials, including logins created for provider applications and board portals, live in an end-to-end encrypted vault. Its contents are encrypted before they leave our devices; the vault provider cannot read them.

Communications — voice and fax, as we use them, run through a business communications service. What arrives there is brought into our own systems rather than left to accumulate with the vendor.

E-signature — completed applications and credentialing documents requiring provider signature are sent through a secure e-signature platform, standard practice in credentialing and document execution. Documents sent for signature include only the information necessary for that specific application.

Whatever the service, two things stay constant: each receives only what its function requires, and provider information is never shared for any purpose beyond the work. Beyond operational services, provider information leaves our systems only as the credentialing work itself requires: submissions to licensing boards, hospitals, and other credentialing bodies, made with the provider's authorization, and the work product of an engagement delivered to the organization that engaged us. We do not sell provider data.

Questions about our security practices

If you have questions about our security practices, how we handle specific types of data, or would like more detail about any aspect of this policy, please reach out directly. We are happy to discuss our practices with prospective or current clients.