Security
Built like the audit is tomorrow.
HIPAA posture isn't a checkbox page here — it's the architecture. Every claim below is verifiable in the platform.
Platform safeguards
Five things that are true of every tenant.
- HIPAA compliant — AWS Business Associate Agreement in place
- Encrypted at rest and in transit
- Postgres row-level security enforces tenant isolation
- Separation-of-duties enforcement on financial actions
- Tamper-evident audit trail on every record change
Minimum necessary, by default
The least data that answers the question.
Client-facing surfaces show authorized hours — never consumption. Caregiver and client identities render as first name and locality unless a role explicitly needs more. It is a default, not a setting somebody has to remember to switch on.
42 CFR 441.301(c)(3)Minn. Stat. § 256B.85Minn. Stat. § 245D
Paperwork
A signed BAA comes standard.
Every tier, every tenant. An AWS BAA is in place upstream as well — there is nothing to negotiate and nothing to ask for.
Systemax
- HIPAA — signed BAA
- Built in Minneapolis
- SOC 2 Type II — in progress