FAQ
Everything you need to know about working with Harmony Administration — from onboarding and pricing to how your information stays secure.
Onboarding begins with a free discovery call where we discuss your needs, working style, and goals. From there, I send a welcome packet with a service agreement, a short intake questionnaire, and secure access to your client portal. Most clients are fully onboarded within 3–5 business days.
You'll share access to the tools you'd like me to manage (email, calendar, CRM, etc.), any existing SOPs or preferences, and a brief list of priorities. Everything is stored securely in your client portal, and an NDA is signed before any work begins.
For most clients, support begins within one week of signing the service agreement. If you need urgent coverage, I offer a rush onboarding option — just mention it during your discovery call.
Yes. A non-disclosure agreement is signed for every professional and executive client before any work or information sharing begins. HIPAA-aware protocols are also in place for healthcare clients.
Pricing is based on monthly retainers, which offer the best value and predictable monthly costs. Retainers include a set number of hours each month at a discounted rate. Hourly support is also available for one-off projects or overflow work.
Monthly retainers are billed month-to-month with no long-term contract. I believe in earning your business every month — if the fit isn't right, you can adjust or cancel with 30 days' notice.
Any hours beyond your monthly retainer are billed at a transparent hourly rate, and you'll always be notified before additional work begins. Unused retainer hours roll over for one month.
Absolutely. If your needs don't fit neatly into a listed plan, we'll build a custom package during your discovery call based on the scope and complexity of the support you need.
All client data is stored in a secure, access-controlled portal with role-based permissions. NDAs are signed before any work begins, and I follow HIPAA-aware protocols for any healthcare-related tasks. Documents and communications are never shared with third parties.
Yes. I am US-based and available Monday through Friday, 8AM to 6PM EST. All work is handled personally — it is never outsourced or passed to a third party.
I recommend using a secure password manager (such as 1Password or LastPass) so you can grant access without sharing raw passwords. Any credentials you do share are stored encrypted and never reused or accessed outside of the work you've assigned.
Yes. I have nearly a decade of experience in healthcare settings, including EPIC training and EMDR workflow support. HIPAA-aware protocols are followed for all protected health information, and I am experienced with clinically significant document handling.
Every user in the system is assigned a role — admin, employee, or client — and each role only sees the data and tools relevant to them. Clients access their own dedicated portal, employees see their assigned tasks and communications, and admins manage operations. No user can view another user's records unless explicitly permitted.
Yes. All portal sessions automatically time out after 15 minutes of inactivity. You'll receive a warning before the session ends, giving you time to extend it. If no action is taken, you're securely logged out and must re-authenticate to regain access.
Document downloads are restricted by role — only authorized admins can download sensitive files. Every download, payroll export, and inbox deletion is recorded in a tamper-evident audit log so there's a complete trail of who accessed what and when.
All internal portal pages display a dynamic watermark with the signed-in user's name and a timestamp. This discourages screen captures and makes any leaked screenshot traceable back to the individual who took it.
Copy, cut, paste, and right-click context menus are disabled for non-admin users across the employee portal. Text selection is also blocked on sensitive content. These controls prevent casual copying of client data, though they cannot stop determined screen-capture tools — which is why watermarks and audit logs provide the second layer of protection.
All public-facing forms — including feedback, job applications, and handover logs — run through server-side input sanitization that strips malicious scripts, tags, and injection attempts before anything is stored. This protects both your data and the system from cross-site scripting and other common web attacks.
All communication between clients, employees, and admins happens through a secure in-app inbox inside the portal — not over email. Messages are tied to authenticated user accounts, restricted by role-based permissions, and deletions are logged for audit purposes.
Every sensitive action — document downloads, payroll exports, inbox message deletions, and administrative changes — is automatically recorded in an audit log with the user, timestamp, and action taken. This creates a complete, reviewable history of activity that supports accountability and compliance.
Book a free discovery call and I'll walk you through exactly how we'd work together.
Book a Free Call