Security & Compliance
Your Parent's Data Deserves Enterprise-Grade Protection
We protect your family's health information with the same rigor that hospitals and health systems require — because coordination only works when you trust the platform.
HIPAA-Compliant by Design, Not Afterthought
HIPAA compliance isn't a checkbox — it's woven into how we build, operate, and monitor our platform. We comply with all applicable requirements of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.
Privacy Rule
We maintain policies governing the use and disclosure of Protected Health Information (PHI), including patient rights to access, amend, and receive an accounting of disclosures of their PHI.
Security Rule
We implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of electronic PHI (ePHI) — covering access controls, audit controls, integrity controls, and transmission security.
Breach Notification Rule
We maintain procedures for identifying, investigating, and reporting breaches of unsecured PHI in accordance with HIPAA requirements, including notifications to affected individuals, HHS, and (where applicable) the media.
Business Associate Agreements
We execute HIPAA-compliant Business Associate Agreements (BAAs) with all third-party service providers who may create, receive, maintain, or transmit PHI on our behalf — ensuring protection extends throughout our supply chain.
How We Protect Your Data
Multiple Layers of Defense in Depth
We don't rely on a single security measure. Every layer of our platform implements controls designed to protect against unauthorized access, data breaches, and system compromise.
Encryption
- All data encrypted at rest using AES-256 encryption
- All data encrypted in transit using TLS 1.3
- Database-level encryption for all Protected Health Information
- Encrypted backups with secure key management
Infrastructure Security
- SOC 2 Type II certified cloud infrastructure
- Network segmentation and firewalls
- DDoS protection and intrusion detection systems
- Regular vulnerability scanning and penetration testing
- 24/7 security monitoring and automated threat detection
Access Controls
- Role-based access controls (RBAC) limiting data access to authorized personnel only
- Multi-factor authentication (MFA) required for all coordinator and administrative access
- Principle of least privilege — coordinators see only their assigned patients
- Session timeouts and automatic logout after inactivity
- Access review and de-provisioning procedures for departed personnel
Audit & Monitoring
- Comprehensive audit logging of all access to Protected Health Information
- Real-time alerts for suspicious access patterns or policy violations
- Regular internal and third-party security audits
- User access review on a quarterly basis
- Log retention in accordance with HIPAA requirements
Personnel & Training
- All coordinators and staff undergo HIPAA compliance training upon hire and annually
- Background checks for all personnel who access patient information
- Confidentiality agreements signed by all employees and contractors
- Security awareness training covering phishing, social engineering, and data handling
- Clear disciplinary procedures for security policy violations
Incident Response
- Documented incident response and breach notification procedures
- Breach notification to affected individuals within 60 days as required by HIPAA
- Notifying the U.S. Department of Health and Human Services for breaches affecting 500+ individuals
- Post-incident root cause analysis and remediation planning
- Tabletop exercises and incident response drills conducted annually
Common Security Questions
Where is my data stored?+
Who can see my parent's health information?+
How do you handle a data breach?+
Do you have Business Associate Agreements with your vendors?+
Can I get a copy of my parent's data?+
Is the platform regularly tested for vulnerabilities?+
Security You Can Trust. Coordination You Can Rely On.
Have more questions about our security practices or HIPAA compliance? We're happy to talk through them — or provide documentation for your review.
