Credentialing Check · Security
Security details for healthcare staffing buyers
What protects your credentialing records today, what is not yet established, and what to confirm before your procurement team approves the service.
Last updated October 6, 2026

Data-use boundary
No PHI. No Business Associate Agreements.
Credentialing Check prohibits protected health information (PHI) uploads and does not sign Business Associate Agreements (BAAs). We do not represent this service as HIPAA-compliant or suitable for workflows that require a BAA.
Use the service for workforce credential records, not patient records, charts, treatment details, or patient-identifiable case logs. Do not paste PHI into AI auto-fill, chat, forms, review notes, or integration payloads.
Clinician health and screening documents can still be sensitive, and whether information is PHI depends on its context. Do not assume all employment documents are exempt. Review and redact documents before uploading; if your workflow requires PHI, use a service with the appropriate agreement and safeguards instead.
If you believe PHI was uploaded accidentally, stop sharing it and contact info@credentialingcheck.com without including the sensitive data in your message.
Agency isolation & document access
Current protections
Agency-scoped permissions separate clinician records, credentials, and client shares. Access depends on agency membership and role; authorized platform administrators have separate administrative access.
Credential files use private storage. Authorized viewers open files through short-lived signed links, not permanent public file addresses. A signed link remains usable until it expires; removing access does not recall copies already downloaded.
Owners, admins, recruiters, clinicians, and invited clients have different permissions. Clinicians can upload renewals but cannot download documents through their portal. Client access is limited to clinicians their agency shares and the download permissions it grants.
Encryption in transit & at rest
HTTPS in use; at-rest specifications not verified
Connections to credentialingcheck.com use HTTPS to encrypt data in transit.
Records and uploaded documents are hosted in managed cloud services. We have not verified a project-specific statement covering encryption at rest for both database records and document storage, including algorithms, key ownership, and rotation. We do not claim customer-managed keys or publish an AES specification without that evidence.
If encryption-at-rest documentation is a procurement requirement, request written confirmation before uploading production data.
Backups, recovery & uptime
No published service-level guarantee
We have not established a published backup schedule, retention period, restore-test cadence, or contractual recovery targets for this service. Database recovery and uploaded-file recovery must be assessed separately; a database backup alone is not evidence that document files can be restored.
Credentialing Check does not currently publish a contractual uptime percentage, recovery point objective (maximum data loss), or recovery time objective (time to restore service). Do not rely on an assumed 99.9% availability commitment.
Keep your original documents and use the available record exports as part of your agency’s continuity process. Exports are not a complete backup of uploaded files. Contact us to review recovery and availability requirements before purchase.
MFA & enterprise SSO
Email/password and Google sign-in available
The application offers email/password and Google sign-in. It does not currently provide an agency-managed MFA enrollment or enforcement interface.
Google-account security controls are managed by your identity provider; Google sign-in is not a promise that Credentialing Check enforces a second factor for every session.
SAML/OIDC enterprise SSO, mandatory MFA, automated user provisioning, and centralized session policies are not offered as configured application features today. Tell us your requirements for assessment; availability requires written confirmation, not an assumption based on hosting-platform capabilities.
Audit history & integration activity
Workflow history available
Clinician activity history records supported clinician and credential workflow actions, including document changes and review approvals or rejections, with actor and timestamp information. Review records can include the verification method, notes, and rejection reason.
The integration module also records inbound and outbound sync activity, direction, outcome, and a summary. It uses hashed API keys and signed webhooks for the supported connections.
This is operational history, not a claim of immutable or tamper-evident audit storage. We do not promise comprehensive logging of every sign-in, record view, download, or administrator action, or a fixed audit-retention period. Discuss any formal audit or SIEM requirements with us first.
Have a security questionnaire?
Send your requirements for encryption, backup recovery, availability, identity controls, and audit retention. We will distinguish documented protections from requirements we cannot currently meet. This page is not a certification or a substitute for a signed agreement.
Related policies: Privacy Policy · Data Processing Addendum
