Security
SECURITY BY INTENTION.
The public site is static and intentionally keeps clinical records out of scope. Before launch, security review must verify hosting configuration, form-vendor controls, headers, monitoring, incident response and approved access paths.