Trust & security

Every finding names its source.

No patient information touches our platform. Every figure we produce is cited to a named source and arrived at by a stated method, so you can check it.

No EHR accessNo PHIEvery finding cited

The short answers

Four questions, asked in every first call.

If the answer to any of these were different, the rest of this page would not be worth reading.

No.

Do you connect to our EHR?

There is nothing to connect. A report never requires access to your systems. A Rounds integration connects only what a practice administrator authorizes, is limited to what that authorization grants, and can be revoked at any time.

No.

Do you receive patient information?

No patient record, chart, claim detail or identifier reaches the platform, so there is no patient information for us to lose.

No.

Do you need billing exports?

Provider NPI numbers, specialty and location are enough. Nothing leaves your billing system, and nothing about your operations has to change while we work.

No.

Do you sell or share what you learn?

Your report is yours. We do not resell findings, aggregate your practice into a product other people buy, or pass your details to anyone for marketing.

Scanner terms

What the free scan does, exactly.

This is the whole behavior of the tool on our homepage, and of the scan that feeds a Prognosis.

What it requests
Publicly accessible pages, fetched the same way a standard web browser fetches them. No login, no credential, no attempt to reach anything behind one.
What it respects
Your robots.txt. If a path is disallowed, we do not fetch it.
What it reads
The served page and its response headers, the documents it links to, your DNS, TLS and mail-authentication records, the cookies the page sets, and the third-party requests it makes on its own. On an assessment scan we also load the page a second time under instrumentation to see which trackers fire.
What it keeps
We keep the URL you enter and the requesting address, for 90 days. After 90 days the address is deleted; the URL is kept, with the country the address came from, the referrer and any campaign parameters that came with your visit, and the time and result of the scan. The address is used only to review abuse of the free tool, and only Ralt staff can see it. We may use the URL to contact you about what the scan found.
What it never does
Submit your forms, create appointments, probe for vulnerabilities, or send traffic you would notice. One read, at browser speed.
Opting out
If you are a practice owner or IT administrator and wish to exclude your domain from our scanning, email privacy@ralthealth.com with the domain. We honor opt-out requests within five business days. The scanner information page says how to identify our traffic.
Point in time
Scan results, scores, and reports are an automated snapshot of a public domain at the time of execution, and web configurations change often. Reports are provided as is, for informational and educational purposes only, and are not a formal legal, compliance (including HIPAA or ADA), or cybersecurity audit. Site owners should verify findings independently before making changes.

Held to our own bar

We run the product against ourselves.

Anyone who receives a Ralt report can scan us back with the same kind of tooling, so this site has to survive the thing it is selling. Here is the bar. Our current result against it is in Still Open below, because we will not publish a grade without the scan behind it.

Security headers

The same complement we grade others against: HSTS enforced, Content Security Policy, clickjacking protection, nosniff and a referrer policy. HSTS is the one we treat as a failure rather than a gap, on our site as on anyone's.

Accessibility

WCAG 2.2 AA including linked documents. The PDFs most scanners skip are exactly what we grade others on, so ours are in scope too.

Trackers

Tracker-minimal by policy. No third-party request a visitor would be surprised by, and any analytics we run is named here and justified in writing.

Common questions

What compliance officers and practice owners ask.

Where does the data come from?

Federal, state and local sources, plus your own website. Claims-level utilization, commercial rate disclosures, demographic and market structure, and workforce and coverage signals. Every figure in a report names the source it came from, so you can go and check it. We may incorporate licensed data, or data a customer chooses to share with us under agreement, never patient information. Any such data is governed by that agreement and named in our subprocessor and retention disclosures.

Do you need a business associate agreement?

A BAA covers the handling of protected health information. We do not receive any, so there is nothing for one to govern. If your compliance process requires the paperwork anyway, we will sign it.

What do you keep after a scan?

The URL, the requesting address, the referrer, and any campaign parameters that came with the visit. The address is deleted after 90 days. If you inquire, whatever you put in the form. Nothing else, and the site sets no advertising or tracking cookies.

Is any of this AI?

The engine is deterministic. A figure is arrived at by a stated method from a named source, and the same inputs produce the same output every time, which is the only way a number can open its receipt.

Who has access internally?

The people who build your report. We are small enough that this is a short list and honest enough to say it is not governed by a formal access-review program yet.

Still open

What we haven't finished.

A trust page that only lists what is already true is a marketing page. These are current as of 11 September 2026.

Site events are logged, not stored

The site sends a few named events, such as a scan started or a form sent, to our own endpoint. That endpoint writes each one to a request log and keeps nothing else. Where events will be stored has not been decided; when it is, the store will be named here before it starts collecting anything.

What we found on our own front doors

We run the same scans on ralthealth.com and app.ralthealth.com that we run on a practice. They have surfaced findings, we have fixed them, and we will keep publishing the ones we have not yet fixed here rather than pretending the scanner spares us.

Our own grade is not currently published

We rescanned this site on 11 September 2026 and the run was partial: our own scanner reached one page of ralthealth.com and none of app.ralthealth.com. A grade from that would describe one page while looking like it described the site, so we are not publishing one. We will publish it when the scan reaches both front doors in full. Both halves or neither is the rule we hold ourselves to.

Only the address has a deletion date

We keep a scan's requesting address for 90 days to review abuse of the free tool, then delete it. The URL, the country, the referrer, and the time and result of each scan have no deletion date yet, and until they do, saying one would be a number without a policy behind it. Ask and we will delete yours.

Closed since the last update: the services that touch this site and our delivery pipeline are listed on the subprocessors page, with what each one handles and whether it signs a BAA.

Security questions go to a person.

There is no security portal and no ticket queue. Write to security@ralthealth.com and one of the people who built this will answer, including when the answer is that we have not done something yet. We respond within one business day and coordinate responsible disclosure timing with you.