Loading...
Loading...
Accounts are created by your organization's administrator. They send you an email invitation with a temporary password; on your first sign-in you will be asked to choose a new password. If your agency is not yet on DrDocs, request early access from the pricing page and our team will set up your organization.
During early access the DrDocs team creates your organization for you. Once you have an admin account, use Organization Configuration to turn modules on or off, set your timezone (used for EVV exports and scheduled reports), configure task categories and scoring, and add branding.
Go to Users and choose Add User → Invite by email. Pick a role (clinician, supervisor, manager, admin, billing, read-only) and we email a temporary password that must be changed on first sign-in. Family members are invited from a patient's detail page under Family portal access.
The web portal works in current versions of Chrome, Safari, Edge and Firefox. The iOS app requires iOS 17 or later and is distributed through TestFlight during early access and the App Store once released. Dictation needs microphone access; visit check-in uses location services.
Sign in, open Settings → Security → Change password, and enter your current and new password (12+ characters with upper- and lower-case letters, a number and a symbol). If you have forgotten it, use Forgot password on the sign-in page to receive a 6-digit reset code by email.
Plans are managed by the DrDocs team during early access — there is no self-service billing portal yet. Email support@drdocs.app with your organization name and we will update your billing details or invoicing contact.
Email support@drdocs.app from an organization admin account. We confirm the cancellation date, and your data remains exportable (CSV/PDF reports, EVV exports) until the account is closed. Audit logs are retained as required by HIPAA.
Early-access customers are invoiced monthly or annually and can pay by ACH or card via the invoice link. Card-on-file self-service billing is planned for a later release.
Check that the device has a network connection and that you are signed in (Settings shows your account). Dictations recorded offline are queued and upload automatically when connectivity returns — open the Offline Queue in Settings to retry a failed item. If the portal shows stale data, pull to refresh or sign out and back in. Still stuck? Open a support ticket with the approximate time and what you were doing.
Make sure DrDocs has microphone permission (iOS Settings → DrDocs → Microphone). Keep the app in the foreground while recording; long recordings are chunked and uploaded securely for transcription. If a transcript never appears, the recording is still stored — retry it from the dictation list or the Offline Queue.
Visit check-in captures your location once when you start and end a visit; it needs Location permission set to While Using. If the address geocode looks wrong, an admin can correct the patient address on the web (it is re-geocoded automatically). EVV records with a location mismatch are flagged as exceptions for a supervisor to review, not silently dropped.
Large organizations should filter list pages by date range or status — lists load 100 rows per page. On iOS, keep the app updated via TestFlight/App Store and free up storage if recordings fail to save. Report exports over long date ranges can take a few seconds; use the CSV export for very large datasets.
All traffic uses TLS; data is encrypted at rest in AWS (RDS, S3, DynamoDB with KMS). Access is role-based and organization-scoped, admins can require two-factor authentication, and sessions time out automatically. Every access to patient data is written to the audit log. See the HIPAA page for the full list of safeguards.
Role-based access with least-privilege roles (including read-only and time-limited auditor access), two-factor authentication, automatic session timeout and admin session revocation, tamper-evident audit logs for PHI access, soft-delete with a 30-day trash, and a Business Associate Agreement available on request.
Encryption in transit (TLS 1.2+) and at rest (AES-256 via AWS KMS) for the database, object storage and backups. Passwords are stored as bcrypt hashes; two-factor secrets are encrypted with a dedicated key. DrDocs does not currently use end-to-end encryption between devices — the service processes PHI server-side to provide transcription and summaries.
Sign-ins, failed sign-ins, password changes, PHI reads, edits, deletions, exports and permission changes are logged with user, timestamp, IP address and user agent. Organization admins can search the audit log in the portal; external auditors can be granted time-boxed read access.