HIPAA
Full compliance with the Privacy Rule, Security Rule, and Breach Notification Rule.
Trust & security
We're a locally owned agency, not a tech company — but HIPAA compliance, AES-256 encrypted backups, audit logging, and AI safety controls were built into every system from day one.
Certifications
HIPAA
Full compliance with the Privacy Rule, Security Rule, and Breach Notification Rule.
HITRUST
Our voice partner RingCentral holds HITRUST CSF certification, the gold standard for healthcare information security.
SOC 2 Type 2
RingCentral's SOC 2+HIPAA report validates controls for security, availability, integrity, confidentiality, and privacy.
ISO 27001
ISO/IEC 27001 certification for information security management, audited annually.
AES-256 encryption
All data at rest is encrypted. Backups are encrypted before offsite storage; financial fields add Fernet encryption.
TLS 1.3
All data in transit protected via Cloudflare. HSTS enforced. No plaintext HTTP connections.
Practices
HIPAA compliance program
We are a covered entity with workforce training, regular risk assessments, incident response procedures, and ongoing monitoring built into every system.
Business Associate Agreements
Signed BAAs with every vendor that touches PHI: Google Cloud, WellSky, RingCentral, Retell AI, and EBizCharge. No BAA, no PHI.
Access controls
Role-based access, Google OAuth with domain restriction, per-user portal scoping, 24-hour sessions, MFA for admins, rate-limited logins.
Audit logging
Every access to PHI is logged: who, what, when. Record changes capture before-and-after snapshots. Logs retained a minimum of 7 years.
Retention & disposal
Client records 7 years per Colorado requirement, operational logs 90 days to 2 years, AI transcripts 7 days, then automatically purged.
Backup & recovery
Daily encrypted backups of all databases and signed documents, weekly restore testing, 7-day local retention, unlimited cloud retention.
AI & Gigi security
Gigi runs on Google Vertex AI under BAA, verifies caller identity before sharing anything, and purges transcripts after 7 days.
Network & infrastructure
Cloudflare WAF and DDoS protection over an encrypted tunnel. Services bind to localhost only. HSTS and CSP enforced. No plaintext credentials in source.
Family-owned agencies run on trust. We invest in the security program because we believe it is table stakes for handling medical information — and most of our peers do not. The same standard applies to who we hire — join our caregiving team.
We will send our latest SOC 2 summary and answer vendor security questionnaires directly. Ask Jason.
Our credentials