Trust & credibility
Five things an ASC compliance lead can verify before piloting.
Five documented integration partners, a DEA-ready audit export, per-case audit replay, and the encryption + role + no-model-training posture that backs them — written for the compliance-side buyer, not for enterprise legal review.
01 · Five documented ASC integration partners
Five documented ASC integration partners.
Anesloop ships adapters against five named systems: Provation for GI rooms, HST for ASC-side practice management, SIS for OR + ambulatory scheduling, and the major EHR surface carried at hospital-affiliated ASCs (Epic) and at multi-specialty sites that run a specialty EHR (Modernizing Medicine). The list is the same five documented on /integrations, with the per-adapter read/write inventory that page carries in plain language your interface team can quote back.
Anesloop is read-only against your chart of record. It does not displace Provation, HST, SIS, or any EHR. The screening output surfaces in the Anesloop pre-op queue, the screening-hold flag lands back on the case row your team already reads at 0630, and the post-op charge capture lands the same day so the morning RCM handoff is complete on day one, not at month-end.
- Provation (GI) — direct DB read against your Provation SQL backend inside your network; no public endpoint, no outbound from your environment to ours.
- HST (ASC practice management) — HL7 v2 over MLLP for ADT, SIU, and ORM order segments terminated inside your network.
- SIS (OR + ambulatory) — HL7 v2 ADT + SIU plus a direct read against SIS scheduling tables for OR-block utilization the morning rebalance runs against.
- Epic + Modernizing Medicine — HL7 FHIR R4 (SMART-on-FHIR for single-patient reads, FHIR Bulk Data Access for the population-level pulls), authorization handled within your identity provider.
- See /integrations for the per-adapter read/write inventory and the connector paths your interface team quotes back.
02 · DEA-ready audit export at month close
DEA-ready audit export at month close.
Every controlled-substance entry captures lot number, witness initials, and wastage at the moment of administration — not in a morning reconciliation that an auditor has to chase. Shift-to-shift count drafts roll up automatically; the monthly packet aligns with the state-specific roles (pharmacist, DEA registrant, prescriber) and Form 41–style reconciliations your surveyor already expects.
At month close, the reconciliation ledger exports as a single artifact your compliance reviewer hands to the auditor or the inspector — a PDF, a pulled period, and a BAA scope that covers the AIMS feed, the EHR connection, and the Anesloop cloud under one agreement. Retention is framed against your state's inspection window and your regulator's record-retention rule, not a fixed calendar date.
- Point-of-administration capture: lot number, witness, wastage — written once at the vial, not re-keyed later.
- Shift-to-shift count drafts roll up; the monthly packet aligns with state-specific roles and Form 41–style reconciliations.
- Exportable at month close as a single artifact (the period pulled, the BAA scope already covered) — not a manual pull by your team.
- Retention framed against your state's inspection window and your regulator's retention rule, not a fixed calendar date.
- A single BAA covers the AIMS feed, the EHR connection, and the Anesloop cloud — compliance signs one agreement instead of three.
03 · Per-case audit replay, exported as one artifact
Per-case audit replay, exported as one artifact.
Every screen view, every clearance edit, every draw on a controlled-substance line gets a row in the audit log. The row records the user, the role, the timestamp, the chart or vial in scope, and the change itself — not a paraphrase of it, the change. For a write event, the row carries a before / after snapshot so the auditor sees what the field held before the line was edited and what it held after.
A post-hoc compliance reviewer replays the case in the order it happened: who opened the chart, who cleared the hold, who witnessed the wastage, who signed off. Pulling that trail for a surveyor or an internal chart review is a single exported artifact, not a meeting with engineering and not a manual SQL pull against your own database.
- Read events captured: chart opens, clearance views, substance-log reads.
- Write events captured: clearance approvals and edits, lot draws, wastage captures, count submissions, sign-offs.
- Audit rows carry user id, role, timestamp, target id, and a before / after snapshot for write events.
- Replay available as a single, exported, documented sequence — not a manual SQL pull by your team.
04 · Security & data-handling posture, summarized
Security & data-handling posture, summarized.
TLS 1.3 only — 1.2 and 1.1 are disabled at the edge. Mutual checks cover the AIMS feed, the EHR connection, and the Postgres wire traffic the Anesloop cloud runs on, so a packet capture on either side does not give an attacker anything they can read.
Two roles define the account model: `user` for clinicians and front-desk staff, `admin` for the people at your ASC who provision and de-provision everyone else. Default role is `user`; no account is born into a privileged tier, and provisioning moves through your admin, not ours. Your records live in the regional Postgres cluster you deploy into — we do not move them into a shared training set, and we do not train, fine-tune, or evaluate any model on PHI that flows through Anesloop without a separate written authorization on file.
- TLS 1.3 only — 1.2 and 1.1 disabled at the edge; modern AEAD cipher suites per session.
- Two roles defined for your deployment: `user` (clinicians and staff) and `admin` (your provisioning team).
- Provisioning and de-provisioning run through your admin, not ours; we hold no standing credentials to your tenant.
- Records live in the regional Postgres cluster you deploy into — no shared training set, no model-training on your data without written authorization.
- See /security for the full controls matrix and the deeper per-control write-up.
Forward internally
Download the ASC-admin overview.
One page covering the four ways Anesloop runs around your chart of record — printable, emailable, ready to forward to a medical director.
What we don't have yet
A testimonials page — and we won't ship one until we can.
The page above is what Anesloop can prove on day one of a pilot. Customer quotes and case studies are deferred until a pilot signs and can be quoted by name; a "trusted by" row or a fabricated case study is not on this site, by design. When the first reference is ready to be quoted, it lands at /testimonials and links back here from the proof list above.
Need the paperwork?
Want the BAA text or our standard controls matrix?
Send a short note from your compliance lead. We reply within one business day with the BAA, the controls matrix, and a list of named references at facilities running Anesloop in production.