Encryption in transit and at rest
All traffic is served over TLS and record storage is encrypted at rest. The in-app data-protection dashboard re-verifies transport, storage and secret handling and shows a pass/fail result per control.
All traffic is served over TLS and record storage is encrypted at rest. The in-app data-protection dashboard re-verifies transport, storage and secret handling and shows a pass/fail result per control.
Caregivers see only the clients they are scheduled with. Contact details, addresses and full names stay masked until a staff member explicitly reveals them — and that reveal is recorded.
Reads, writes, exports, denied attempts and break-glass access are written to an immutable audit log with actor, office, record type and timestamp, filterable and exportable for review.
Integration credentials and API keys carry rotation targets. Scheduled compliance scans re-check them daily and email administrators whenever a control changes state.
Download a HIPAA readiness evidence pack covering office scope, control results, rotation status, remediation worklist, scan history and PII-scrubbed audit entries — the download is itself logged.
The product targets WCAG 2.1 AA: keyboard-operable workflows, visible focus, semantic landmarks, colour-independent status indicators and text alternatives throughout.
Compliance staff keep a vendor roster inside the admin area with Business Associate Agreement status, risk level and outstanding request tasks — so you always know which subprocessors have signed and which are still open.