Skip to main content
Security & compliance

In healthcare operations, trust is the product.

Metolius handles the operations behind patient care — credentialing records, claims, payer contracts, and the data underneath them. The security posture is the starting point, not a retrofit.

The posture

Enterprise-grade by default.

Every organization on the platform gets the same controls — there is no "enterprise tier" for security.

SOC 2 Type II

Independently audited controls covering security, availability, and confidentiality.

HIPAA-compliant operations

PHI is handled under HIPAA-compliant process, not as an afterthought bolted onto a general-purpose tool.

Enterprise SSO

Your identity provider and your access policies — not a separate password estate to manage.

Role-based access control

Least privilege across entities: the right people see the right sites, and nothing more.

Full audit logging

Every action on the record, across every entity in the network, available for review.

Enterprise SLAs

Service levels in writing — and the dashboard that measures performance against them.

How we operate

What that looks like day to day.

Access is scoped by entity

Multi-entity organizations get boundaries that match their real structure, so one site's team never sees another's data by default.

Operators work in the open

The dedicated team works your queues inside PracticeOS — the same system you watch — so there is no black box between the work and the record of it.

The posture is inherited, not improvised

Metolius runs on Continuant's enterprise security posture, built over three decades serving the world's largest health systems and insurers.

Bring your security review. We expect it.

We are used to enterprise diligence — send your questionnaire and we will work through it with your team.