Designed for HIPAA safeguards · BAA required before PHI activation

Enterprise-grade security built for healthcare.

Your residents’ data deserves the highest level of protection. CareBridge Connect is designed for healthcare privacy and security, hosted on SOC 2 Type II-certified AWS infrastructure, encrypted in transit and at rest.

Certifications & Standards

We meet and exceed the security standards required by healthcare organizations and regulatory bodies.

HIPAA Safeguard Design

Designed to support the HIPAA Privacy, Security, and Breach Notification Rules. A BAA and launch approval are required before a facility may process PHI through the platform.

SOC 2-Audited Infrastructure

Hosted on Amazon Web Services (AWS), which maintains SOC 2 Type II certification, under a signed AWS Business Associate Agreement. Our own SOC 2 Type II audit is on the roadmap.

AES-256 Encryption at Rest

All data at rest is encrypted using AES-256, the same standard used by financial institutions and government agencies.

TLS 1.2+ in Transit

Data transmitted between your devices and our servers is protected with TLS 1.2 or newer using a modern CloudFront security policy.

Infrastructure Partners

We partner with industry-leading infrastructure providers that maintain the highest levels of security certification.

Amazon Web Services (AWS)

SOC 2 Type II, signed BAA

Cloud infrastructure for application hosting, database, and authentication — with row-level security, encryption at rest and in transit, a global CDN, and automatic SSL certificate management.

Amazon SES

Covered under the AWS BAA

Transactional email for care notifications and demo requests, sent from the same HIPAA-eligible AWS environment as the rest of the platform — no third-party email processor touches your data.

Data Protection

  • PHI never leaves US infrastructure
  • Encryption at rest (AES-256)
  • Encryption in transit (TLS 1.2 or newer)
  • Row-level security — each facility's data is isolated
  • 99.9% uptime SLA

Access Controls

  • Role-based access: Admin, Staff, Primary Family, Family
  • Audit logging on all PHI access events
  • Session management with automatic timeout
  • Multi-factor authentication support

Compliance

We maintain rigorous compliance standards to ensure your facility meets all regulatory requirements.

  • HIPAA Business Associate Agreement (BAA) executed with every facility before any PHI is processed
  • CMS data retention standards — 7-year audit log retention
  • Regular security reviews and vulnerability assessments
  • Incident response and breach-notification timelines defined in the BAA and applicable law
  • Resident/family authorization workflows for every PHI disclosure

Questions about security?

Our security team is available to discuss your compliance requirements, review our security documentation, or schedule a security assessment call.

Contact Security Team

security@carebridgeconnect.ai