Everything Podlantic runs — credentialing, recruiting, referrals, marketing, practice admin — touches your practice, your payers and your people. It does not touch patient records. That is a design decision, not a limitation we're working around.
What that means for you. No Business Associate Agreement to negotiate. No offshore subcontractor attestation to file with CMS. No entry in your HIPAA risk analysis for an overseas vendor. No state-by-state restrictions on where we can work. And no six-week compliance review before we can start.
No PHI doesn't mean no discipline. This is how every pod works, for every client.
Background and reference checks on every person before they join a pod.
Every pod member works under their own account with a defined role — never a shared password.
A complete, reviewable record of who did what, when — across every system a pod touches.
Multi-factor authentication on every account a pod member uses to reach your systems.
OIG and SAM.gov exclusion checks on every pod member — re-run monthly, not once at hiring.
A written commitment: any security incident affecting your data is notified within 24–72 hours.
Security and compliance questions go straight to the people who own them — not a support queue. If your compliance officer or attorney needs specifics, we'll put them in the room.
security@podlantic.com