CERTIFICATIONS AND COMPLIANCE

Certified. Compliant. Auditable.

Glenwood Systems maintains current ONC Health IT certification for GlaceEMR, operates HIPAA-compliant infrastructure across the platform, and supports e-prescribing of controlled substances through Surescripts EPCS. The credentials, the posture, and the documentation are all on this page.

Active Credentials

PROGRAM

ONC Certified Health IT

GlaceEMR is certified under the ONC Health IT Certification Program, 2015 Edition Cures Update. Annual Real World Testing plan and results published per 45 CFR § 170.405. Certifying body: Drummond Group LLC.

Listing on CHPL →

INFRASTRUCTURE

HIPAA-Compliant Platform

Enterprise-grade security architecture across the Glace platform. Business Associate Agreements (BAAs) in place with all subcontractors that touch PHI. Access controls, immutable audit logs, and breach-notification procedures meet HIPAA Security Rule requirements.

Security posture detail below ↓

PRESCRIBING

EPCS via Surescripts

Electronic Prescribing of Controlled Substances enabled through Surescripts, with Id.me identity proofing and multi-factor authentication at signing time. DEA requirements for controlled-substance e-prescribing (21 CFR Part 1311) are met by default.

Interoperability Standards

GlaceEMR exchanges data with the systems your practice already depends on. Standards-based, no proprietary lock-in.

Modern APIs

  • FHIR R4 with full USCDI v3 coverage for patient-access APIs (SMART on FHIR + OAuth 2.0 + OpenID Connect).
  • FHIR Bulk Data Access (Flat FHIR) for population-level queries.
  • OpenGlace API for partner integrations beyond FHIR scope.

Legacy and ambulatory standards

  • HL7 v2.x messages for hospital interfaces (ADT, ORM, ORU, MFN, SIU) across 15+ hospital systems.
  • C-CDA (Consolidated CDA) send and receive for transitions of care.
  • Direct Secure Messaging for provider-to-provider clinical communication.
  • CareQuality participation for nationwide health-information exchange.
  • NCPDP SCRIPT for e-prescribing (via Surescripts).
  • X12 837/835/270/271/277/278 for claims, ERA, eligibility, and prior authorization.

Integrations

  • Labs: Quest Diagnostics, Labcorp, BioReference, and 50+ regional labs (60+ total).
  • Hospitals: 15+ named systems including Northwell Health, McLaren, BayCare, Baystate.
  • Pharmacies: nationwide via Surescripts.
  • Claims clearinghouse: Etactics.
  • Specialty devices: ECG, Echo, Holter, spirometry, CGM (Dexcom, Libre), insulin pumps (Tandem, Medtronic, Omnipod), and more.

Security Posture

Enterprise-grade security, top to bottom. Each control aligns to HIPAA Security Rule administrative, physical, and technical safeguards.

Administrative safeguards

  • Designated Security Officer and Privacy Officer with documented responsibilities.
  • Annual workforce HIPAA training; tracked completion records.
  • Annual risk assessment per the HIPAA Security Risk Analysis methodology.
  • Business Associate Agreements (BAAs) with every subcontractor that touches PHI; standing BAA available to customers on request.
  • Documented incident-response plan with defined roles, escalation paths, and breach-notification timelines.

Technical safeguards

  • Role-based access control with least-privilege defaults and named-user identity for every login.
  • Multi-factor authentication available; required for EPCS signers, administrative roles, and remote access.
  • Immutable audit logging of every record access, modification, and export; logs retained per HIPAA retention requirements.
  • Automatic session timeout and password complexity policy.
  • Emergency-access procedure (break-glass) with full audit trail.
  • End-to-end TLS 1.2+ for all data in transit; standard cipher-suite hardening.

Physical safeguards

  • PHI data is hosted on enterprise-grade cloud infrastructure with documented physical-access controls and 24/7 monitoring.
  • Workforce device security policy including disk encryption requirements for any device with PHI access.

Need our security questionnaire response, SOC report, or BAA template? Email moreinfo@glenwoodsystems.com. We respond within two business days.

Patient Access Rights

Patients have a federally protected right to access their electronic health information. Glenwood Systems supports this through every certified access pathway.

  • Patient portal: web and mobile, English and Spanish. Lab results, visit summaries, immunizations, problem lists, medications, allergies, and secure messaging.
  • Patient FHIR API: OAuth-authorized third-party apps can access USCDI v3 data on the patient’s behalf.
  • Download (View, Download, Transmit / VDT): patient-initiated electronic export to a destination of the patient’s choosing.
  • Designee access: patients can designate a representative (e.g., a caregiver) for portal access with audit trail.

Public Compliance Documents

Statements + Pages

Published PDFs

For documents available on request, including standard BAA template, security questionnaire response (SIG Lite and HECVAT), SOC report summary, penetration-test attestation, incident-response plan summary, and disaster-recovery plan summary, contact moreinfo@glenwoodsystems.com.

Compliance Contact

For compliance, security, or certification questions:

Email: moreinfo@glenwoodsystems.com
Phone: (888) 452-2363
Mail: Glenwood Systems, LLC · 1389 West Main Street, Suite 308 · Waterbury, CT 06708

See What Glenwood Can Do for Your Practice

A 20-minute working call. We show you the platform on your specialty’s actual workflows, not a generic demo.