Security and compliance

Built like the audit is tomorrow.

Medicaid clawbacks are triggered by documentation gaps, not hackers. So our security model covers both: protecting PHI and making non-compliant billing structurally impossible.

Where we are today, stated plainly

No clinic PHI is stored anywhere in our systems today; the public tour runs entirely on sample data. HIPAA has no certification to wave around; it is a set of legal obligations that attach when a clinic signs a Business Associate Agreement and real records begin to flow. We do not sign that agreement until every piece of infrastructure beneath it has signed its own. The cards below describe how the platform is engineered and exactly what activates, in writing, before your first real record enters. A vendor that claims more than this before their first clinic is telling you something about how they will handle your audit.

A signed BAA comes before your first record

We become your business associate the day a Business Associate Agreement is signed, before any PHI enters the system. Breach notification duties and minimum-necessary access are contractual from onboarding day one, never aspirational.

Encrypted by design, hosted under BAAs

The platform is engineered for TLS 1.2+ on every connection and AES-256 at rest, and production PHI will live only on infrastructure that signs its own BAA with us. If a vendor will not sign, your data does not touch it.

Role-based access, enforced in the product

RBTs see their own clients. Caregivers see their own child. Owners see aggregates, never another family’s clinical detail. This is not a policy document; it is the role engine you can test in the public tour right now.

Tamper-evident audit logging, built in

Every view, edit, signature, claim attempt, and refused booking is designed to log actor, role, and timestamp, with six-year retention to match Medicaid documentation expectations. Watch the events fire in the tour; even blocked attempts become defensible history.

EVV integrity by design

Visit verification captures real device GPS or an honestly labeled attested exception. Coordinates are never fabricated, and exceptions are never dressed up as verified. That behavior is in the engine, not the marketing.

Documentation-gated billing

No claim can exist without a signed, validated note, an active authorization, and a current credential. Security here means your revenue survives an audit, not just that the database is locked.

Own your data, in writing

Complete export of your clinic’s data at any time, in open formats, free, written into your agreement. Data portability is a security property: it means you are never hostage to us.

Incident response with named timelines

A written incident response plan with defined notification timelines is part of the HIPAA program we stand up before the first clinic goes live. If something ever goes wrong, you hear it from us first, with specifics.

Where we are on SOC 2, stated plainly

Our controls are built against the SOC 2 Type II trust criteria, and a formal Type II audit is our committed next milestone. We will publish the auditor and the audit window here the day the engagement begins, and the report the day it exists. What we will never do is claim a certification we do not hold; if a vendor’s security page cannot say that sentence, ask why.

Nothing on this page is legal advice; it is a description of our own program and commitments.