Private by design, not just by policy

Bridge surfaces the chart a clinician already has open, in their own session, on their own device. Nothing has to be transmitted for an app to work out whether a patient is relevant, which removes most of the exposure before any control is applied to it.

  • HIPAA
  • BAA available
  • SOC 2 Type I complete
  • Type II in progress
  • Independent penetration testing
  • Chrome and Edge
TB1 · CLINIC WORKSTATION · BROWSERTB2 · EHR TAB · EHR ORIGIN · USER'S OWN SESSIONTB3 · IFRAME · YOUR ORIGINEHR pagechart the physician has openBridge runtimecontent scriptcontext in tab memory onlydiscarded on navigateYour appyour rules + your UIdecides in the tabnothing sent to decideService workerextension backgroundArrowhealth backendsign-in · app config · healthno patient data storeYour backendyour systems · your BAAwith the clinicF1read · open chartDOM, in tabF2postMessage / MessagePortin the tab · never the SWF3HTTPS · on physician actionreferral / formF4sign-in · telemetry · no PHIF5TLS 1.2+no PHI
F1F2in the tab

Your rules run in the physician's session

Bridge reads the open chart and hands it to your app inside the browser, under the physician's own EHR sign-in. Your app decides what to show on the spot and updates as they move between charts, with nothing sent to make the call.

  • Only the chart on screen, only while it's open
  • Held in tab memory, dropped on navigate
  • Runs as the physician. No service account
F3on the physician's action

The record goes straight to you

When the physician refers, enrolls or submits, your app sends that record directly to your servers. Bridge frames your app and signs the physician in, but the patient data never passes through us.

  • HTTPS to your own endpoint
  • Covered by your BAA with the clinic
  • What leaves is visible in your own traffic
F4F5control plane

Our servers never hold patient data

Bridge's backend handles sign-in, which app and settings to load, and health signals like errors and versions. It has no patient data store, and patient context is never routed through it.

  • Sign-in, app config, health telemetry
  • TLS 1.2+ in transit
  • We sign a BAA with you as subprocessor

The architecture does most of the work

Four properties of how Bridge runs, rather than four things bolted on afterwards.

Context stays in the tab

Patient context is assembled when the clinician opens a chart, held in that tab’s memory while they are viewing it, and discarded when they navigate away.

Bridge stores none of it

Bridge does not write patient context to storage and does not transmit it to a Bridge server. Producing it requires no round trip through our backend.

Your app keeps what it needs, in your systems

The SDK passes the open chart to your app. Anything your app saves goes to your own backend, under your BAA with the clinic. Bridge doesn’t keep a copy.

Evaluation happens on the device

Rules are fetched once and run locally, so for the patients who do not qualify — most of them — nothing has to be transmitted at all.

Where Arrowhealth sits

Your app holds the Business Associate Agreement with the clinic. Arrowhealth operates as a subprocessor to you and signs a BAA with you covering Bridge's role. We do not enter a direct relationship with the clinic. Where a clinic requires subprocessor disclosure, you can list Arrowhealth accordingly.

Our backend telemetry is operational health only: status codes, error types, integration failures and version information. It is designed to exclude patient data. Because it is generated from live clinical sessions we do not represent that incidental patient data can never appear in a telemetry event; the pipeline is built to avoid it, and anything incidental is covered under our BAA.

Security program

SOC 2
A Type I examination is complete. A Type II examination is in progress.
Penetration testing
Independent third-party tests at least annually against systems handling confidential data.
Vulnerability management
Internal and external scans at least quarterly, with critical findings addressed within days.
Encryption
Confidential data encrypted in transit with TLS 1.2 or higher, and encrypted at rest.
Access control
Access to production systems is role-based and reviewed.
Incident response
A documented incident-response process is maintained.
Vendor management
Vendors and subprocessors with access to confidential data are reviewed.

Who is responsible for what

Arrowhealth
Surfacing chart context locally, the extension and its updates, the SDK boundary, and our own infrastructure and operational telemetry.
Your app
Anything the app does with the context it receives — persistence, transmission and audit — through your own backend and under your own BAA with the clinic.
The clinic
Device and browser integrity, and how the extension is deployed and kept current where extensions are centrally managed.

Documentation on request

The full Bridge security overview, the SOC 2 report and a BAA are available to enterprise customers on request, under NDA.