Security
OperHand Security
Version 2026-09-02 ยท Effective on publication
How OperHand protects the information pharmacies entrust to it. A plain statement of the
controls in place at the version date above. It is not a certification and not a warranty:
controls may change, and the Customer Agreement governs. How personal information is handled
is set out separately in our Privacy Policy.
- Encryption: Patient identity and contact fields are encrypted by the
application before storage. Signed documents and signature images are held in private,
access-controlled storage. Data is encrypted in transit.
- Separation: Every pharmacy's data is isolated; every query is scoped to
one pharmacy.
- Access: Four fixed roles enforced server-side. Multi-factor
authentication is mandatory on OperHand's own administrative accounts, and available to
pharmacy accounts, which each pharmacy may require of its own staff.
- Support access: OperHand personnel have no default access to patient
data. Support access is read-only, single-pharmacy, time-limited, reason-required and
written to the audit log, which pharmacies may request.
- Audit log: Append-only; never edited or deleted.
- Patient links: Single-use for signing, date-of-birth verified,
rate-limited, expiring.
- Messages: Emails and texts contain no medical detail.
- Bill: Runs only when staff launch it, acts under that person's identity,
sends no screen images to OperHand.
- Storage: United States, with the providers listed on our Sub-processors
page, each under a written data-protection agreement.
- Backups: Provider point-in-time recovery; restores are drilled
periodically.
- Assurance: an internal privacy and security assessment maintained by
OperHand. This statement is the means by which our safeguards are described to customers;
security questionnaires, assessments and on-site audits are not provided.
OperHand is a business name of Heaven Surge Inc., Ontario, Canada.
โ Back to the overview