Your Patient Data Never Leaves Your Practice

Most practice management add-ons upload your patient data to someone else's cloud. refract.ing does the opposite.

refract.ing installs directly on your practice's own Windows server — the same server that runs your OfficeMate (Eyefinity) SQL database. All patient data processing happens locally, inside your firewall, on hardware you control.

On-Premises Architecture

refract.ing connects to OfficeMate's built-in SDK stored procedures for read-only database access. There is no cloud relay, no data warehouse, no third-party hosting of your patient records. PHI stays on your network, period.


Business Associate Agreements

refract.ing provides a Business Associate Agreement (BAA) to every practice before any patient-communication features are enabled. This is not optional — we require it.

To request a BAA, email dr@refract.ing. We typically execute within 48 hours.


Technical Safeguards

Encryption

All data in transit between system components is encrypted using TLS 1.2 or higher. Database connections to OfficeMate use SQL Server's native encryption capabilities.

Access Controls

Audit Logging

Every system action is logged with timestamps, user identification, and action details. Audit logs are stored locally and available for review during compliance assessments.

Network Isolation

Security Assessments

refract.ing undergoes regular security assessments of its codebase, dependencies, and deployment procedures. Identified vulnerabilities are remediated before release.


Administrative Safeguards

Built by a Practicing Optometrist

refract.ing was created by Dr. Alexander Bonakdar, OD — a practicing optometrist in Irvine, CA who deals with HIPAA requirements in his own practice every day. This is not a Silicon Valley startup learning healthcare compliance after the fact. The platform was designed from the ground up by someone who understands both the regulatory obligations and the clinical workflow.


About This Website

It is important to distinguish between the refract.ing marketing website (what you are reading now) and the refract.ing product (the on-premises software installed in practices).

This Website Does Not Process PHI

HIPAA Applies to the On-Premises Product

The HIPAA compliance measures described on this page apply to the refract.ing software installed on practice servers — the system that connects to OfficeMate and processes patient data locally. The marketing website and the clinical product are completely separate systems with no shared data.


Questions About Compliance?

Dr. Bonakdar is available to discuss HIPAA compliance, BAA execution, or security specifics directly.

Email dr@refract.ing →