This page is published by Geach Technologies, LLC, trading as ChartVoyant (“ChartVoyant”, “we”, “us”), of Cleveland, Tennessee. It describes how we back up the product and how production is built to stay available. It is not a claim that any system is perfectly secure.
1. What this page covers
It covers ChartVoyant production: the EMR, this website, and the related services we operate on Amazon Web Services in the United States. It does not replace the written services agreement and business associate agreement that govern a practice deployment. Where those conflict with this page, those control.
The public demo runs on synthetic sample data only. Real patient records are accepted only under a signed BAA, on the production system described here.
2. Daily backups, and more often than daily
We take encrypted backups of the production database and the document store at least once every day, so a day’s work is not a single copy on a single disk. In production, AWS Backup also snapshots those stores every six hours. Aurora PostgreSQL keeps a continuous point-in-time recovery window in the primary region.
Each backup is copied to a second United States region (us-west-2) so a
failure of the primary region is not the loss of the only copy. Daily and six-hourly
recovery points are kept for 35 days; a monthly copy is kept for a year.
That is how we stay prepared for disaster recovery: there is always a recent, encrypted, off-site copy of the database and of the documents that belong with it. A restore that recovered records without their documents would not be a restore.
3. High availability
Production runs in us-east-1 under a signed AWS business associate
agreement. The application is deployed across multiple availability zones, with more
than one application task behind a load balancer so a single task or zone going down
does not take the product with it. The database is an Aurora cluster with a replica.
Traffic is encrypted in transit.
Live probes for every ChartVoyant surface are published at status.chartvoyant.com.
4. Disaster recovery
The adopted recovery targets are a 24-hour recovery point (RPO) — no more than a day of data at risk — and a 72-hour recovery time (RTO) to restore service. Daily backups (and the six-hourly snapshots on top of them), plus the second-region copies, are how those targets are met. If the product is unavailable, customer practices follow their own downtime procedures; our obligation is to communicate status and restore service.
5. What this page does not promise
The public website and demo are offered as-available under the Terms of Service. This page is not an uptime guarantee, not a warranty, and not a substitute for a practice’s own downtime plan. No system is perfectly secure, and we do not claim otherwise.
6. Changes
We will post any revision here and update the effective date above.
7. Contact
Geach Technologies, LLC (trading as ChartVoyant), Cleveland, Tennessee · info@chartvoyant.com · (762) 887-8412. Questions about a practice deployment belong with that practice’s services agreement and BAA, not this page.