Protecting data at every layer.
From encryption and access controls to payment tokenization and audit trails, security is embedded in everything we build.
Built following HIPAA administrative, physical, and technical safeguards
Payments processed through a PCI Level 1 Compliant service provider
SMS consent management with opt-in, opt-out, and detailed audit trail
Security is not a checkbox.
It's an ongoing practice.
We take a layered approach to protecting the data that dental practices and their patients trust us with. From encrypted infrastructure and strict access controls to real-time monitoring and detailed audit trails, every part of the platform is designed with security in mind.
We host on security-certified cloud infrastructure with Business Associate Agreements in place, and we maintain internal security practices including automated testing, code scanning, and continuous error monitoring. We invest in security alongside every feature and update we ship.
Healthcare Data Protection
Smile Advantage is built following HIPAA requirements and best practices to safeguard patient health information. We maintain Business Associate Agreements with our hosting provider, payment processor, and service providers.
Encryption
All data is encrypted at rest and in transit using industry-standard methods. Database storage and backups are encrypted, and sensitive fields within the application receive additional layers of protection.
Payment Security
Payments are processed through a Level 1 PCI Compliant service provider. Credit card data does not touch or reside in Smile Advantage systems. All payment methods are securely tokenized by the processor, so only non-sensitive reference data is retained for display.
Network Protection
The Smile Advantage platform is protected by a web application firewall, bot detection, and DDoS mitigation. All connections are served over HTTPS, and traffic is monitored and filtered before it reaches the application.
Access Controls
Role-based permissions ensure staff only see what they need. Accounts require verification, and authentication is rate-limited to help prevent unauthorized access. Password policies are informed by current NIST guidelines.
Session Security
Sessions automatically time out after a period of inactivity, and extended sessions require re-authentication. All session data is stored server-side, and session events are captured in an audit trail.
Audit Trail
Important platform actions are logged, including but not limited to authentication, enrollments, payments, communications, and profile changes. Every record includes user attribution and timestamps, and records are retained in accordance with our data retention policies.
Data Isolation
The platform uses a multi-tenant architecture with practice-level data boundaries. Patient and member data is scoped to each office, with authorization checks applied to every operation and data request.
Privacy in Analytics
Protected health information is not sent to third-party analytics services. Only non-identifying, office-level business metrics are tracked.
SMS Compliance
Our text messaging system is designed for TCPA compliance with automatic STOP keyword opt-out, and a detailed audit trail. Consent records are append-only and never modified.
Administrative Safeguards
All third-party vendors and subprocessors that handle sensitive data are vetted for security, privacy, and compliance standards before integration. Business Associate Agreements are required where applicable, and vendor relationships are reviewed on an ongoing basis.
Code Quality & Monitoring
Every feature goes through automated testing before deployment. Our development process includes code scanning for security vulnerabilities, static analysis, and pre-commit quality checks. In production, errors are captured and monitored in real time with centralized logging.
A note on regulatory compliance
Smile Advantage is a membership management and payment processing platform. Our platform and features are designed to align with HIPAA, PCI, and TCPA requirements for our own operations as described on this page.
We do not provide state-specific membership agreement templates, legal review, regulatory compliance guidance, or legal protection for your practice's membership plans. If your state requires specific licensing or disclosures for discount medical or dental plans, we recommend consulting with a qualified attorney or compliance advisor.
Questions about security?
If you have any security questions or want to report a security concern, please reach out to our team at support@smileadvantage.com or call (314) 885-4640 .
Ready to see the platform in action?
Schedule a demo to see how Smile Advantage protects patient data while helping your practice grow its membership program.