Security & Compliance

Your Parent's Data Deserves Enterprise-Grade Protection

We protect your family's health information with the same rigor that hospitals and health systems require — because coordination only works when you trust the platform.

HIPAA-Compliant by Design, Not Afterthought

HIPAA compliance isn't a checkbox — it's woven into how we build, operate, and monitor our platform. We comply with all applicable requirements of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.

Privacy Rule

We maintain policies governing the use and disclosure of Protected Health Information (PHI), including patient rights to access, amend, and receive an accounting of disclosures of their PHI.

Security Rule

We implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of electronic PHI (ePHI) — covering access controls, audit controls, integrity controls, and transmission security.

Breach Notification Rule

We maintain procedures for identifying, investigating, and reporting breaches of unsecured PHI in accordance with HIPAA requirements, including notifications to affected individuals, HHS, and (where applicable) the media.

Business Associate Agreements

We execute HIPAA-compliant Business Associate Agreements (BAAs) with all third-party service providers who may create, receive, maintain, or transmit PHI on our behalf — ensuring protection extends throughout our supply chain.

How We Protect Your Data

Multiple Layers of Defense in Depth

We don't rely on a single security measure. Every layer of our platform implements controls designed to protect against unauthorized access, data breaches, and system compromise.

Encryption

  • All data encrypted at rest using AES-256 encryption
  • All data encrypted in transit using TLS 1.3
  • Database-level encryption for all Protected Health Information
  • Encrypted backups with secure key management

Infrastructure Security

  • SOC 2 Type II certified cloud infrastructure
  • Network segmentation and firewalls
  • DDoS protection and intrusion detection systems
  • Regular vulnerability scanning and penetration testing
  • 24/7 security monitoring and automated threat detection

Access Controls

  • Role-based access controls (RBAC) limiting data access to authorized personnel only
  • Multi-factor authentication (MFA) required for all coordinator and administrative access
  • Principle of least privilege — coordinators see only their assigned patients
  • Session timeouts and automatic logout after inactivity
  • Access review and de-provisioning procedures for departed personnel

Audit & Monitoring

  • Comprehensive audit logging of all access to Protected Health Information
  • Real-time alerts for suspicious access patterns or policy violations
  • Regular internal and third-party security audits
  • User access review on a quarterly basis
  • Log retention in accordance with HIPAA requirements

Personnel & Training

  • All coordinators and staff undergo HIPAA compliance training upon hire and annually
  • Background checks for all personnel who access patient information
  • Confidentiality agreements signed by all employees and contractors
  • Security awareness training covering phishing, social engineering, and data handling
  • Clear disciplinary procedures for security policy violations

Incident Response

  • Documented incident response and breach notification procedures
  • Breach notification to affected individuals within 60 days as required by HIPAA
  • Notifying the U.S. Department of Health and Human Services for breaches affecting 500+ individuals
  • Post-incident root cause analysis and remediation planning
  • Tabletop exercises and incident response drills conducted annually

Common Security Questions

Where is my data stored?+
All data is stored on SOC 2 Type II certified cloud infrastructure within the United States. We use industry-leading cloud providers with comprehensive physical and environmental security controls. Data is never stored on coordinator or employee personal devices.
Who can see my parent's health information?+
Only your dedicated coordinator and the family members you authorize. Our administrative staff do not have access to individual patient records. Every access is logged and auditable. You control which family members have access and at what level.
How do you handle a data breach?+
We maintain a documented incident response plan aligned with HIPAA Breach Notification Rule requirements. In the unlikely event of a breach affecting unsecured PHI, we would notify affected individuals within 60 days (as required by HIPAA), provide details about what occurred and what information was involved, and outline steps we're taking to investigate, contain, and prevent recurrence.
Do you have Business Associate Agreements with your vendors?+
Yes. Every third-party service provider that may create, receive, maintain, or transmit PHI on our behalf is required to sign a HIPAA-compliant Business Associate Agreement (BAA). This legally binds them to the same privacy and security standards that apply to us.
Can I get a copy of my parent's data?+
Yes. You have the right to access and receive copies of your parent's PHI in a portable format. We will respond to access requests within 30 days, as required by HIPAA. Contact your coordinator or our Privacy Officer to initiate a request.
Is the platform regularly tested for vulnerabilities?+
Yes. We conduct regular vulnerability assessments, penetration testing, and security audits — both internally and through independent third-party security firms. Findings are tracked, prioritized, and remediated on a defined schedule. We also perform annual HIPAA security risk assessments.

Security You Can Trust. Coordination You Can Rely On.

Have more questions about our security practices or HIPAA compliance? We're happy to talk through them — or provide documentation for your review.