Skip to content
Security

Built like the audit is tomorrow.

HIPAA posture isn't a checkbox page here — it's the architecture. Every claim below is verifiable in the platform.

Platform safeguards

Five things that are true of every tenant.

  • HIPAA compliant — AWS Business Associate Agreement in place
  • Encrypted at rest and in transit
  • Postgres row-level security enforces tenant isolation
  • Separation-of-duties enforcement on financial actions
  • Tamper-evident audit trail on every record change
Minimum necessary, by default

The least data that answers the question.

Client-facing surfaces show authorized hours — never consumption. Caregiver and client identities render as first name and locality unless a role explicitly needs more. It is a default, not a setting somebody has to remember to switch on.

42 CFR 441.301(c)(3)Minn. Stat. § 256B.85Minn. Stat. § 245D
Paperwork

A signed BAA comes standard.

Every tier, every tenant. An AWS BAA is in place upstream as well — there is nothing to negotiate and nothing to ask for.

Proof, not promises

Audit-ready by default.

Systemax

  • HIPAA — signed BAA
  • Built in Minneapolis
  • SOC 2 Type II — in progress