Security & Compliance
Built like the audit is tomorrow.
Home health runs on trust: patients trust the nurse, agencies trust the record, surveyors trust the evidence. Here is, in plain language, how CareSign protects all three.
HIPAA-ready by design
CareSign runs entirely on HIPAA-eligible cloud services (Google Cloud for application data, AWS for transactional email) under Business Associate Agreements. Protected health information stays inside that covered infrastructure.
No PHI in email
Every email CareSign sends, from signing requests to confirmations and digests, carries secure links and neutral language, never clinical content. The sensitive material lives behind authentication or single-use tokens.
Encryption in transit and at rest
All traffic is TLS-encrypted. Data is encrypted at rest by our cloud providers. Signing links use 256-bit single-use tokens that are stored only as SHA-256 hashes. We couldn't leak the raw token if we tried.
Per-agency tenancy isolation
Every record is scoped to an agency, and server-side security rules enforce that boundary on every read and write, including file storage. We audit our rules for provability, not just intent.
Role-based access control
Admins, office staff, QA reviewers, and field nurses each see exactly what their role needs. Access is enforced with authentication claims on the server, not hidden buttons in the UI.
Immutable audit trail
Every create, update, and delete is recorded server-side in an append-only log: actor, action, timestamp, and the fields that changed. No user, including administrators, can rewrite history.
US data residency
Application data is stored in United States cloud regions.
Least-privilege operations
Production access is limited and logged. Scheduled jobs and integrations run as dedicated service accounts with narrowly scoped permissions.
Synthetic demo data
Product demos and evaluations run on a synthetic demo agency: invented patients, invented visits. Real PHI is never used to sell software.
Signature evidence
How a signature becomes evidence
- 1
Capture
A signature is collected at the bedside, by QR, by link, or through a physician queue. Captured alongside it: signer role, capacity attestation, GPS, and device context.
- 2
Seal
The completed record is fingerprinted with SHA-256 and registered in a tamper-evidence registry, and a verification code and certificate are issued.
- 3
Verify
Anyone with the code (a surveyor, an attorney, the patient's family) can confirm the record's authenticity at a public verify page, without an account and without exposing PHI.
A note on HIPAA, honestly
There is no such thing as a "HIPAA-certified" software product. Anyone who tells you otherwise is selling something. HIPAA compliance is a shared responsibility: CareSign provides the safeguards described on this page and enters into Business Associate Agreements with customer agencies, and your agency's policies, training, and access practices complete the picture. We're happy to walk your compliance officer through the details.
Found a security issue? Please report it to admin@caresignhealth.com. We take reports seriously and respond quickly.
Bring your compliance officer
The fastest way to evaluate CareSign's posture is a demo with the person who signs off on it. We'll show the audit trail, the evidence registry, and the tenancy rules live.