Trust & security

Your family's data, protected like a hospital's

We're a locally owned agency, not a tech company — but HIPAA compliance, AES-256 encrypted backups, audit logging, and AI safety controls were built into every system from day one.

HIPAA
HITRUST
SOC 2 Type 2
ISO 27001
AES-256
TLS 1.3

Certifications

Independently verified, not self-claimed

HIPAA

Full compliance with the Privacy Rule, Security Rule, and Breach Notification Rule.

HITRUST

Our voice partner RingCentral holds HITRUST CSF certification, the gold standard for healthcare information security.

SOC 2 Type 2

RingCentral's SOC 2+HIPAA report validates controls for security, availability, integrity, confidentiality, and privacy.

ISO 27001

ISO/IEC 27001 certification for information security management, audited annually.

AES-256 encryption

All data at rest is encrypted. Backups are encrypted before offsite storage; financial fields add Fernet encryption.

TLS 1.3

All data in transit protected via Cloudflare. HSTS enforced. No plaintext HTTP connections.

Practices

What we actually do, day to day

HIPAA compliance program

We are a covered entity with workforce training, regular risk assessments, incident response procedures, and ongoing monitoring built into every system.

Business Associate Agreements

Signed BAAs with every vendor that touches PHI: Google Cloud, WellSky, RingCentral, Retell AI, and EBizCharge. No BAA, no PHI.

Access controls

Role-based access, Google OAuth with domain restriction, per-user portal scoping, 24-hour sessions, MFA for admins, rate-limited logins.

Audit logging

Every access to PHI is logged: who, what, when. Record changes capture before-and-after snapshots. Logs retained a minimum of 7 years.

Retention & disposal

Client records 7 years per Colorado requirement, operational logs 90 days to 2 years, AI transcripts 7 days, then automatically purged.

Backup & recovery

Daily encrypted backups of all databases and signed documents, weekly restore testing, 7-day local retention, unlimited cloud retention.

AI & Gigi security

Gigi runs on Google Vertex AI under BAA, verifies caller identity before sharing anything, and purges transcripts after 7 days.

Network & infrastructure

Cloudflare WAF and DDoS protection over an encrypted tunnel. Services bind to localhost only. HSTS and CSP enforced. No plaintext credentials in source.

Most home care agencies don't do this.

Family-owned agencies run on trust. We invest in the security program because we believe it is table stakes for handling medical information — and most of our peers do not. The same standard applies to who we hire — join our caregiving team.

Ask us a security question →

Need a BAA, a security questionnaire, or a privacy review?

We will send our latest SOC 2 summary and answer vendor security questionnaires directly. Ask Jason.

Our credentials

  • Licensed Colorado home care agency
  • Fully bonded & insured
  • VA Community Care Network provider
  • Background-checked caregivers
  • Locally owned & operated
  • Family Room care portal
  • Serving Colorado since 2012