HomeServicesPlanCase studiesSecurityAboutContactDigital SolutionsHospice & Palliative EHRMarketingCRMTelecommunicationAI AutomationBook a consultation
HIPAA compliant by design

Patient data, protected like it's our own.

Hospice runs on trust, from families, from referral sources, from CMS. Every HospiNotes engagement runs under a signed Business Associate Agreement from day one, with encryption, least privilege access and complete audit logging on every chart we touch. No exceptions.

AES 256encryption at rest
of access logged & monitored
Signed BAA, day oneevery engagement, no exceptions

The safeguards on every chart.

Four pillars that make "HIPAA compliant" more than a checkbox.

Encrypted end to endTLS 1.2 or higher in transit, AES 256 at rest. PHI is never stored or moved in the clear.
Least privilege accessRole based controls and MFA mean staff see only the records their role requires.
Complete audit trailEvery view, edit and export is logged, who, what and when, with zero exceptions.
Signed BAA, alwaysA Business Associate Agreement is in place before we touch a single chart.
Access & identity

The right people. Only the right records.

Access to PHI is scoped to the minimum each role needs and enforced with multi factor authentication. When a team member's role changes or ends, access changes with it. Immediately, not at the next review cycle.

Role based access control: minimum necessary by default.
Multi factor authentication on every account with data access.
Immediate deprovisioning when roles change or staff depart.
Workforce HIPAA training for everyone who touches your charts.
Scribe · role: documentationChart access: assigned patients only
Scoped
MFA challengeVerified before session start
Passed
Offboarded accountAccess revoked in real time
Revoked
Chart viewed. Mrs. J.P.User, timestamp & reason logged
Logged
Note editedChange history retained
Tracked
Record set export. ADRExported under audit trail
Audited
Monitoring & response

If it touches a chart, it's on the record.

Every interaction with PHI is logged and monitored, and our environment is continuously watched for anomalies. If something ever looked wrong, you'd hear it from us first, with a clear breach notification protocol aligned to HIPAA timelines.

Immutable audit logs for every view, edit and export.
Continuous monitoring for unusual access patterns.
Documented incident response with HIPAA aligned notification.
Encrypted backups so your records are recoverable, not lost.
HIPAA compliant by design

Want the full security brief?

We'll walk your compliance team through our BAA, encryption, access controls and incident response plan, so you can say yes with confidence.

Security questions.

The answers your compliance officer will want.

Do you sign a BAA?
Always, and before any work begins. A Business Associate Agreement is a non negotiable part of onboarding, we won't touch a chart without one in place.
Is patient data used to train AI models?
No. PHI is never used to train models. Our AI Automation tools assist review with a human always in the loop, and patient data stays within your protected environment.
How is data encrypted?
PHI is encrypted in transit with TLS 1.2 or higher and at rest with AES 256. It is never stored or transmitted unencrypted at any point in our workflow.
What happens if there's a breach?
We maintain a documented incident response plan with breach notification aligned to HIPAA timelines. You'd be informed promptly, with a clear account of what happened and what's being done, no silence, no surprises.