HIPAA
We operate a HIPAA compliance program covering the Privacy, Security, and Breach Notification Rules. HIPAA has no official certification — compliance is an ongoing practice, not a badge.
Trust & security
We're a locally owned agency, not a tech company — but HIPAA compliance, AES-256 encrypted backups, audit logging, and AI safety controls were built into every system from day one.
Certifications
HIPAA
We operate a HIPAA compliance program covering the Privacy, Security, and Breach Notification Rules. HIPAA has no official certification — compliance is an ongoing practice, not a badge.
HITRUST
Our voice partner RingCentral holds HITRUST CSF certification, the gold standard for healthcare information security.
SOC 2 Type 2
RingCentral's SOC 2+HIPAA report validates controls for security, availability, integrity, confidentiality, and privacy.
ISO 27001
Our voice partner RingCentral maintains ISO/IEC 27001 certification for its information security management system, audited annually.
AES-256 encryption
All data at rest is encrypted. Backups are encrypted before offsite storage; financial fields add Fernet encryption.
TLS 1.3
All data in transit protected via Cloudflare. HSTS enforced. No plaintext HTTP connections.
Practices
HIPAA compliance program
We are a covered entity with workforce training, regular risk assessments, incident response procedures, and ongoing monitoring built into every system.
Business Associate Agreements
Signed BAAs with every vendor that touches PHI: Google Cloud, WellSky, RingCentral, Retell AI, and EBizCharge. No BAA, no PHI.
Access controls
Role-based access, Google OAuth with domain restriction, per-user portal scoping, 24-hour sessions, MFA for admins, rate-limited logins.
Audit logging
Every access to PHI is logged: who, what, when. Record changes capture before-and-after snapshots. Logs retained a minimum of 7 years.
Retention & disposal
Client records 7 years per Colorado requirement, operational logs 90 days to 2 years, AI transcripts 7 days, then automatically purged.
Backup & recovery
Daily encrypted backups of all databases and signed documents, weekly restore testing, 7-day local retention, unlimited cloud retention.
AI & Gigi security
Gigi runs on Google Vertex AI under BAA, verifies caller identity before sharing anything, and purges transcripts after 7 days.
Network & infrastructure
Cloudflare WAF and DDoS protection over an encrypted tunnel. Services bind to localhost only. HSTS and CSP enforced. No plaintext credentials in source.
Family-owned agencies run on trust. We invest in the security program because we believe it is table stakes for handling medical information — and most of our peers do not. The same standard applies to who we hire — join our caregiving team.
We will send our latest SOC 2 summary and answer vendor security questionnaires directly. Ask Jason.
Our credentials