Security
You are trusting us with records that identify people receiving care in their homes. This page describes what we actually do, in terms specific enough to check.
What we do not claim
We are not SOC 2 certified and we do not hold ISO 27001. We are a small company and those audits are ahead of us, not behind us. If your procurement process requires them today, we are not yet the right vendor and we would rather say so here than three weeks into a sales conversation.
There is also no such thing as HIPAA certification. No body certifies software as HIPAA compliant. What HIPAA requires is a set of safeguards and a signed business associate agreement. CareVerify is built to support HIPAA compliance, and the rest of this page sets out exactly what that means in practice.
How your data is protected
Encryption
All traffic runs over TLS. Data is encrypted at rest in the database, in file storage and in backups. Visit records captured offline on a caregiver's phone are held in the app's encrypted local storage until they sync.
Tenant isolation at the database layer
Every record is scoped to an agency and isolation is enforced by Postgres row level security, not by application code. This distinction matters more than it sounds. Application-level checks fail when a developer forgets one query. A database-level policy denies the row even if the query asking for it is wrong.
Audit logging
Every read and write to a client record is logged with who, what and when. Records are retained for 6 years, which is what HIPAA requires. Manual corrections to a visit require a written reason and never overwrite history, so the original entry and the correction both remain visible.
Access control and sessions
Roles determine what each person sees. A caregiver sees only their own assigned clients and visits, never the full client list. Admin web sessions time out after 15 minutes idle. The mobile app requires biometric or code re-entry rather than staying open indefinitely on a phone that gets left on a kitchen counter.
Where your data lives
Application data is stored in the United States, and our team accesses it from the United States when providing support or investigating a fault. That access is role-restricted and logged like any other. If that ever changes, we will say so here and in our privacy policy rather than leave you to find out.
What we deliberately do not collect
The safest data is the data that was never captured. These are design rules, not preferences.
- No client names in error reports or analytics. Crash reports carry technical diagnostics. Product analytics carry usage patterns. Neither receives protected health information.
- No client names in push notifications. A notification saying "Visit with Margaret Chen at 2pm" on a lock screen is a disclosure to anyone standing nearby. Ours says "Your 2pm visit".
- No continuous location tracking. Location is captured at check-in and check-out only. We do not record where a caregiver goes between visits, and the product could not answer that question if you asked it to.
- No clinical records. No diagnoses, medications or assessments. CareVerify is not a clinical system, so that category of data never enters it.
- No advertising trackers in the application. No tracker is ever placed on a screen showing client information.
When something goes wrong
If we discover a breach of unsecured protected health information, we notify affected customers without unreasonable delay and no later than 5 business days after discovery. HIPAA permits 60 days. We commit to 5 because you have your own notification duties and cannot start them until you hear from us.
Our notice tells you what happened, when we found it, which records were involved so far as we can identify them, and what we have done about it. We send it while the investigation is still running rather than waiting for a complete picture.
Service status and incident history are published at status.getcareverify.com. Because caregivers check in offline and the app never blocks a check-in, an outage on our side does not stop visits being recorded. They sync when connectivity returns.
Reporting a vulnerability
If you find a security issue, email security@getcareverify.com. We acknowledge within one business day.
We will not pursue legal action over a good-faith report. Please do not access another agency's data, degrade the service, or disclose the issue publicly before we have had a reasonable chance to fix it.
The paperwork your compliance officer will want
- Business associate agreement, published in full. Free on every plan.
- Subprocessors, every vendor listed with what data it touches and whether it handles PHI.
- Data retention policy, how long we keep records and what happens if you leave.
- Privacy policy, what we collect and how to exercise your rights.
Questions we get asked
Is CareVerify HIPAA certified?
No, and neither is any other vendor. There is no such thing as HIPAA certification. No government body certifies software as HIPAA compliant. Any vendor claiming a HIPAA certification is either confused or hoping you are. What exists is a set of required safeguards and a signed business associate agreement, and we can show you both.
Where is our data stored?
Application data, including all client and visit records, is stored on infrastructure in the United States. Static website content is served from Cloudflare's global edge network, but that content contains no customer data.
Who on your team can see our client records?
Access is role-restricted and limited to staff who need it to provide support or investigate a fault. Every access is written to the audit log, including ours. We do not browse customer data, and an access without a support reason attached is something we treat as an incident.
Will you sign a business associate agreement?
Yes, on every plan, at no extra cost. Our standard BAA is published in full so you can read it before contacting us rather than after.
What happens if there is a breach?
We notify affected customers without unreasonable delay and no later than 5 business days after discovery, which is deliberately tighter than the 60 days HIPAA allows. You need time to meet your own notification duties.
Still have a question?
Security questions go straight to the people who built the system, not to a form.
