HIPAA-compliant architecture · BAA with every facility

Enterprise-grade security built for healthcare.

Your residents’ data deserves the highest level of protection. CareBridge Connect is built on HIPAA-compliant architecture, hosted on SOC 2 Type II-certified AWS infrastructure, encrypted in transit and at rest.

Certifications & Standards

We meet and exceed the security standards required by healthcare organizations and regulatory bodies.

HIPAA-Compliant Architecture

Built to the HIPAA Privacy, Security, and Breach Notification Rules. A BAA is executed with every facility before any PHI is processed through the platform.

SOC 2-Audited Infrastructure

Hosted on Amazon Web Services (AWS), which maintains SOC 2 Type II certification, under a signed AWS Business Associate Agreement. Our own SOC 2 Type II audit is on the roadmap.

AES-256 Encryption at Rest

All data at rest is encrypted using AES-256, the same standard used by financial institutions and government agencies.

TLS 1.3 in Transit

All data transmitted between your devices and our servers is protected with TLS 1.3, the latest transport security protocol.

Infrastructure Partners

We partner with industry-leading infrastructure providers that maintain the highest levels of security certification.

Amazon Web Services (AWS)

SOC 2 Type II, signed BAA

Cloud infrastructure for application hosting, database, and authentication — with row-level security, encryption at rest and in transit, a global CDN, and automatic SSL certificate management.

Amazon SES

Covered under the AWS BAA

Transactional email for care notifications and demo requests, sent from the same HIPAA-eligible AWS environment as the rest of the platform — no third-party email processor touches your data.

Data Protection

  • PHI never leaves US infrastructure
  • Encryption at rest (AES-256)
  • Encryption in transit (TLS 1.3)
  • Row-level security — each facility's data is isolated
  • 99.9% uptime SLA

Access Controls

  • Role-based access: Admin, Staff, Primary Family, Family
  • Audit logging on all PHI access events
  • Session management with automatic timeout
  • Multi-factor authentication support

Compliance

We maintain rigorous compliance standards to ensure your facility meets all regulatory requirements.

  • HIPAA Business Associate Agreement (BAA) executed with every facility before any PHI is processed
  • CMS data retention standards — 7-year audit log retention
  • Regular security reviews and vulnerability assessments
  • Incident response and breach-notification timelines defined in the BAA and applicable law
  • Patient/family authorization workflows for every PHI disclosure

Questions about security?

Our security team is available to discuss your compliance requirements, review our security documentation, or schedule a security assessment call.

Contact Security Team

security@carebridgeconnect.ai