1.Scope
MolarPlus is operated by Upclick Labs (OPC) Pvt. Ltd. (“MolarPlus”, “we”). This statement describes the administrative, physical and technical safeguards MolarPlus applies to protected health information (“PHI”) that dental practices in the United States create, receive, maintain or transmit through the MolarPlus clinic management service. It refers to the Privacy, Security and Breach Notification Rules at 45 CFR Parts 160 and 164.
2.Roles
A dental practice that transmits health information electronically in connection with a standard transaction, such as a claim, is a covered entity. A service provider that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate under 45 CFR 160.103. MolarPlus acts in that capacity for the practices that use it.
3.Security Rule safeguards
The table below sets the standards of the Security Rule against the measures MolarPlus has in place for electronic PHI.
4.Safeguards in detail
- Encryption at rest
- Patient and clinic records are held in a managed PostgreSQL database on Amazon RDS, encrypted at rest with AES-256. The storage volumes of the application servers are encrypted in the same way.
- Encryption in transit
- Every connection between a browser or the MolarPlus mobile app and the MolarPlus service is encrypted with TLS.
- Network isolation
- The production database accepts no connections from the public internet. It can be reached only from the MolarPlus application servers.
- Role-based access
- The clinic owner decides, section by section, what each staff member can see and do. Staff are given access to the information their work requires and nothing more.
- Authentication
- Every user signs in with an individual account. Passwords are stored only as bcrypt hashes, sign-in and sign-up are verified with one-time codes, and repeated attempts are rate limited.
- Audit trail
- Actions taken within a clinic account are recorded in an activity log, which the clinic owner can review and export.
- Private document links
- Documents, prescriptions and reports are kept in private object storage and are opened only through signed links that expire shortly after they are issued.
- Backups and recovery
- The database is backed up automatically every day, with point-in-time recovery available across a rolling seven-day window.
- Portability
- A clinic owner can download a complete archive of the clinic’s data at any time and export patient records as a spreadsheet, without contacting MolarPlus.
5.Privacy Rule support
6.Breach notification
Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery. MolarPlus will notify an affected practice without unreasonable delay. To the extent possible, MolarPlus will identify each individual affected and provide the other information the practice needs to notify individuals, the Secretary of Health and Human Services and, where required, the media.
7.Data location and providers
PHI is stored on Amazon Web Services in the Asia Pacific (Mumbai) region, India. The HIPAA Rules do not prohibit the storage of PHI outside the United States. The service providers MolarPlus uses are listed in the register of sub-processors.
Optional features pass limited PHI to those providers: WhatsApp and SMS reminders send a patient’s name, telephone number and the message content to the messaging provider, and AI-assisted note drafting sends the content a clinician submits. Each practice should decide whether to enable these features in light of its own obligations under the HIPAA Rules.
8.Business Associate Agreements
A practice that requires a Business Associate Agreement should contact MolarPlus at support@molarplus.com before entering PHI into the service.
9.Contact
Questions about this statement or about the security of the service may be sent to: