Our Dr. Rounds+ Application is HIPAA compliant with ePHI.
The Dr. Rounds+ Application is password/PIN protected. No one can access the data on the iDevice unless the PIN is entered correctly. When the phone returns to standby mode (default 1 min), the App is not accessible without re-entering the PIN. Moreover, we encourage locking the iDevice with a master PIN that is different than the one used to access the App.
We use a highly sophisticated encryption of data as it resides on the iDevice and utilized upon data transfer electronically. Data cannot be intercepted or read by anyone but the designated recipient, who will need to be provided an unlock password for data access. This password is generated by the sender and can be communicated to the recipient by means other than electronically.
With data transmitted from the Dr. Rounds+ WebApp Portal to any iDevice, we use what we call "Throw Away Encryption" - this means we create a random encryption key, encrypt the data, and send the recipient the key to download on their iDevice. This and only this key can decrypt the data (which is stored on the server for a limited time). Upon data decryption once (you only get one download) or 72 hours has passed, ALL data beyond this time limit is irrecoverably purged. None of our administrators can even access any of this information. Our site, portal, and servers use Starter SSL (TM) connections, satisfying HIPAA regulation. Data decryption is impossible without the Dr. Rounds+ Application.
The data contained within a typical Dr. Rounds+ record calls for the minimum information required to generate a super-bill, not a medical record. Charges are then sent via secure encrypted, zipped and PIN protected email to your billing staff. Dr. Rounds+ is not an EMR and therefore not intended for the storage of data detailing history and physical findings.
Remote Data purging of a lost iDevice is a service provided by Apple within the MobileMe platform.
Secure data backup and restore is also done via encryption and protected by the native anti-virus and anti-spyware software on the user's personal computer via the iTunes and/or SyncDocs platforms.
As far as the safety of the data on the iDevice, devices should be using iOS 4.0 and greater and a password lock screen - this combination allows for the entire device to be secure, ensuring that even in the event of a lost iPhone the client data is securely encrypted and cannot be obtained.