Patient data stays between the clinic and you

Bridge puts your product beside the patient chart, in the clinician's browser. It doesn't store patient data or send it through Arrowhealth's servers.

  • HIPAA
  • BAA included
  • SOC 2 Type I
  • Independent penetration testing

No patient data stored

Bridge holds the open chart in the browser while the clinician is viewing it, and drops it when they move on. It keeps no copy, and our servers have no patient data store.

  • Held in browser memory
  • Dropped when the chart closes
  • No patient data store on our servers

Not routed through our servers

Bridge hands the chart to your app inside the browser. When your app sends something, it goes straight to your systems, not through Arrowhealth.

  • Your app → your systems
  • Under your BAA with the clinic
  • What leaves is visible in your own traffic

Within the clinician's permissions

Bridge works through the clinician's own EHR sign-in and sees only what they can see. It has no service account and can't pull other patients' records.

  • The clinician's own EHR sign-in
  • No service account
  • Only the chart on screen

A more private approach to patient information

Data exchange between the clinic and your app happens locally, inside the clinician's browser session, the same place the EHR already runs.

EHRClinician opens a patient chart.
BridgeRecognizes the patient and makes context available locally.
Your appUses the context to power its workflow inside the EHR.
Arrowhealth servers

Sign the clinician in and load your app. No patient data passes through them.

Your systems

Your app communicates directly with your systems when needed.

  1. Open a patient chart

    Bridge recognizes the patient and relevant information within the clinician's existing EHR session.

  2. Make context available

    Information is shared locally within the browser. It doesn't need to pass through Arrowhealth's servers.

  3. Your app communicates

    When information needs to be submitted or saved, your app communicates directly with your own systems, not through Arrowhealth.

Security isn't just a team at Arrowhealth

It's built into how the whole company works, from who we hire to how every change ships.

Access

Only vetted people can reach our systems.

  • Multi-factor authentication for production
  • Access by role, least privilege
  • Background checks before access is granted
  • Access removed within 24 hours of leaving

How we build

Every change is reviewed before it ships. Every update to the extension is reviewed by Google too.

  • Built and tested apart from production
  • Systems hardened to CIS and NIST baselines
  • Distributed only through the Chrome Web Store, never sideloaded
  • Manifest V3: only the code Google reviewed can run

How we run

We monitor, test and rehearse.

  • Continuous monitoring and alerting
  • External scans monthly, a penetration test yearly
  • Incident response tested yearly
  • Encrypted in transit (TLS 1.2+) and at rest (AES-256)

Oversight

Independently examined.

Request the report →
  • SOC 2 Type I: security, availability, confidentiality
  • Type II in progress
  • Risk committee with independent members, quarterly
  • Annual risk assessment and vendor reviews

Different roles. Shared security.

Bridge makes context available. Your app determines how to use it.

Bridge

  • Surfaces patient and encounter context locally, within the clinician's browser
  • Operates within the clinician's existing EHR permissions
  • Does not store patient data or route it through Arrowhealth's servers
  • Maintains the security and availability of the Bridge platform

Your app

  • Receives the open chart from Bridge, inside the browser
  • Determines what information to use, send or keep
  • Communicates directly with your own systems
  • Follows your own security practices and compliance obligations

Common security questions

View full security documentation →
Does Bridge store patient information?
No. Bridge holds the open chart in the browser while the clinician is viewing it, and drops it when they move on. It isn't saved to the computer or to Arrowhealth's servers.
Does patient information pass through Arrowhealth's servers?
No. Our servers sign the clinician in, load your app and its settings, and check that everything is running. When your app sends patient information, it goes from the browser to your own systems.
Does Bridge have unrestricted access to the EHR?
No. Bridge works through the clinician's own EHR sign-in, with their permissions, and only for the chart on screen. It has no service account and can't search or download records in bulk.
Is Bridge independently audited?
Yes. Our SOC 2 Type I examination is complete and Type II is in progress. An independent firm tests our systems every year.
Will Arrowhealth sign a BAA?
Yes. Your app holds the BAA with the clinic, and we sign one with you as your subprocessor. The clinic doesn't need a separate agreement with us.

Documentation on request

We share the full Bridge security overview, our SOC 2 report and a BAA under NDA.