Isolation between providers
Every record in Patient360 belongs to exactly one provider, and that boundary is enforced by the database itself through row-level security — not by the application, and not by the interface. No provider can read another provider’s records, even if a request were crafted by hand. The single documented exception is our own named administrators, described below.