Security and compliance: protecting the data your residents trust you with
AssistedCare is HIPAA compliant: JWT authentication, role-based access control, per-organization data isolation, ESIGN/UETA-aligned e-signatures, audit trails and secure storage protect PHI at every layer. Security isn't a feature we bolted on, it's how the platform is built.
Defense in depth: security at every layer
A consistent set of controls applied across the entire platform.
- Authenticated access
- JWT-based authentication with bcrypt-hashed credentials. Inactive accounts are blocked at login.
- Role-based access control
- Granular roles (Super Admin, Staff) scope every screen and API to exactly what a user should see.
- Per-tenant data isolation
- Each organization only ever sees its own communities and residents, enforced at the application layer.
- Compliant e-signatures
- ESIGN/UETA-aligned document signing with SHA-256 hashing, signature certificates and audit logging.
- Audit trails
- Signed clinical notes are immutable; edits and re-signs are recorded with a full audit history.
- Hardened by default
- Rate limiting, request timeouts and secure token handling protect every endpoint.
- Secure file storage
- Documents are stored in object storage and served through short-lived, presigned URLs.
- Least-privilege everywhere
- Server-controlled status and signature metadata, never trusted from the client.
Our commitments: built for healthcare from the ground up
We make security decisions so your team can focus on care, without wondering whether a record is exposed or a document is shared too widely.
- PHI protected with strict facility-level scoping
- Encryption in transit (TLS) across the platform
- Object storage access via short-lived presigned URLs
- Server-side validation on every write
Sign-in on shared devices, backups and getting your data out
- PIN sign-in and idle sign-out
- PIN quick sign-in locked to your facility network for staff on shared facility devices, with automatic idle sign-out so an unattended tablet at the nurses' station does not stay signed in.
- Hourly encrypted off-site backups
- Hourly encrypted backups to independent off-site storage, plus a written, tested disaster-recovery runbook, so your records survive anything that happens to a server.
- Per-organization isolation
- Every PHI record is tied to a facility, and a facility belongs to one organization, so each organization only ever sees its own communities and residents.
- Data export, always
- Residents, financials, reports and documents export to CSV, Excel and PDF at any time, from inside the product. Your records are yours — there's no lock-in and no exit fee.
Security FAQ
- Is AssistedCare HIPAA compliant?
- Yes. AssistedCare is HIPAA compliant: role-based access control, per-tenant isolation, audit trails, encrypted backups and secure storage protect PHI at every layer. Operators remain responsible for their own BAAs, policies and workforce training as part of their overall compliance program.
- How is resident data separated between organizations?
- The platform enforces per-tenant data isolation. Every PHI record is tied to a facility, and a facility belongs to one organization, so users only ever see data within their own organization's communities.
- How are documents stored and shared?
- Uploaded documents live in object storage and are accessed through short-lived presigned URLs rather than public links, so files aren't exposed to anyone without an authenticated, scoped request.
- What happens when a clinical note is signed?
- Signing verifies the signer's account password, applies an e-signature block and locks the note. Signed notes are immutable; any later change requires an explicit unlock, edit and re-sign, all of which are captured in the audit trail.
Care for your residents. We'll protect the data.
Book a demo and see a platform that takes security as seriously as you do. Have a security question? Talk to us.