Mon–Fri, 8:00am – 5:00pm501 NE 23rd Ave, Gainesville, FL
For referring practices

What happens to a prescription after you press Send

You are trusting us with a patient's details. This page says, in plain words, how the provider portal protects them — and what we have not finished yet.

Encrypted in transit and at rest · one practice cannot see another · every view logged · BAA signed

How it is protected

Encrypted in transit

Every page of the portal and every upload travels over HTTPS. Inside our own systems, the hop that carries a prescription from the portal to the record store, and the hop to the file store, are each encrypted too, with certificates we issue and check ourselves.

Encrypted at rest

The database lives on an encrypted volume (AES-XTS, 512-bit key) that is unlocked at boot without a person typing a passphrase into a screen. Uploaded documents are stored with server-side encryption. Backups are encrypted separately, with their own keys.

One practice cannot see another

Every record carries the identity of the supplier it belongs to, and the database itself refuses to return a row to anyone else. This is enforced below the application, so a bug in a page cannot reach across it.

Every view is recorded

When a member of GCM staff opens a referral, downloads a prescription or changes its status, an entry is written to an append-only log with who, what and when. Nothing can edit or delete that log, including us.

Access is by named account, and it times out

Staff sign in with individual accounts; there is no shared login. A session expires after ten minutes without activity and after twelve hours regardless. A screen left unattended blurs its contents after two minutes and comes back on a touch.

The file itself is what is checked, not its name

An uploaded document is identified by its contents, not by the filename or the type the browser claims, before it is stored. Files are served back only through a signed-in session, never from a public address.

No third parties in the page

The portal loads no analytics, no fonts, no scripts from anyone else. A page that loads nothing from outside cannot leak a referral number to outside.

A Business Associate Agreement is in place

Gator Custom Mobility and the company that builds and runs this system, AppDev GNV / Mendoza Bros, have a signed Business Associate Agreement. The system is operated under the HIPAA Security Rule obligations that agreement carries.

What we ask you to send, and not send

The portal is the place for the prescription, the patient’s contact details and insurance. Please do not send those by email or by our public contact form — neither is a secure channel, and both say so on the page.

Inside the portal, send what the order needs and no more. We keep referral records only as long as the order and our record-keeping obligations require.

Prescriptions and patient details go through the portal, never email

What we have not finished

Security pages that claim everything are the ones not worth reading. These are the items still open on our own list, so you can judge for yourself.

  • Multi-factor sign-in for staff is not yet required; staff sign in with a strong password from a restricted network.
  • A full restore of the encrypted backups has not yet been rehearsed end to end; that drill is scheduled.
  • Alerting on unusual access is not yet automated; the audit log is reviewed by a person.

Questions, or a security concern

If you have a compliance officer who wants more detail, or you believe information has been exposed, call the shop and ask for the owner. We would rather hear it today.

Call 352-373-9673 Provider portal sign-in

Mon–Fri, 8:00am – 5:00pm. Closed Saturday and Sunday.