HACKER Q&A
📣 throwme2wolves

Is TextExpander considered a security liability?


A little background on this question:

Healthcare provider productivity has captivated my attention, and I've noticed that a huge issue is note taking and document creation.

Many independent providers don't have the budget for Epic, or the time to create things in Dr. Chrono / other down market EHRs.

So a solution many seem to flock to is TextExpander - which is truly a great user experience that should be 'prebuilt' into the OS (and with Mac it kind of is, not sure about Windows).

All this goes to say, when I downloaded TextExpander, it asked for full accessibility permissions, which technically makes sense. How else would TE get the shortcut command?

However, when thinking of the nature of work performed (legal, healthcare or otherwise, including personal info), I'm curious to know if anyone has kicked the tires on TextExpander's security.

So throwing this out to the community, CIOs, devs and the like: How do you evaluate integrating TextExpander into your organization? Are you auditing the expected performance of TE? Any best practices?

Thanks!


  👤 lloyddobbler Accepted Answer ✓
Hello - Kipp from TextExpander here. Great question that we get a lot (and rightfully so - security is of paramount importance to both our customers and us).

We wrote up a brief FAQ on the topic of snippet security here: https://textexpander.com/learn/accounts/security/how-textexp...

…and you can see our general security practices info here (including that we have a SOC 2 security certification): https://textexpander.com/security

In the healthcare space, we often see practitioners using fill-in snippets to input patient information or notes into an EHR or other system while keeping a standard format to improve searchability. In the interest of security, personally-identifiable info (PII) entered into a fill-in snippet is ephemeral, and remains on the user's local machine. You can learn more about fill-ins here: https://textexpander.com/learn/using/snippets/advanced-snipp...

Please feel free to drop me a note with any further Q's - happy to help.