Your patient data is protected by the highest standards of security and privacy. We're not just compliant — we're committed.
Policies and procedures that manage the selection and execution of security measures.
Protection of electronic systems, equipment, and data from physical threats.
Technology and policies that protect data and control access to it.
AES-256 encryption for data at rest and TLS 1.3 for data in transit. All PHI is encrypted before storage.
AES-256 · TLS 1.3MFA required for all provider accounts. Supports biometric, SMS, email, and authenticator apps.
MFA RequiredComplete audit trails of all access to PHI. Who viewed what, when, and from where.
6-Year RetentionGranular permissions based on user roles. Principle of least privilege enforced.
RBACGeographically redundant, encrypted backups with point-in-time recovery.
30-Day RetentionRegular third-party penetration testing and vulnerability assessments.
Quarterly TestsReal-time security monitoring with automated threat detection and alerting.
SIEM · IDS/IPSAll vendors sign BAAs and undergo security reviews before accessing PHI.
BAA RequiredAs your Business Associate, we sign a comprehensive BAA that outlines our responsibilities for protecting PHI. We're not just a vendor — we're a partner in compliance.
All paid CareSuite plans include a signed BAA. We'll work with your legal team to ensure all requirements are met.
Enterprise customers receive customized BAAs
Complete implementation of patient privacy protections
Administrative, physical, and technical safeguards in place
48-hour breach notification protocol established
Civil money penalty compliance and investigation procedures
Final rule implementing HITECH Act requirements
Enforced access controls and data minimization
In the unlikely event of a breach involving unsecured PHI, we notify affected individuals, the HHS Secretary, and (if applicable) media within 60 days as required by the HIPAA Breach Notification Rule. Our average response time is under 48 hours.
All employees complete mandatory HIPAA training annually with quarterly refreshers.
100% completion rate
Specialized training for developers, support staff, and administrators.
Quarterly updates
Advanced certification for security team members (CISSP, CISM, HCISPP).
85% certified
Achieved HITRUST CSF certification, demonstrating the highest level of information protection.
Successfully completed SOC 2 Type II audit with zero findings.
Awarded ISO 27001 certification for information security management.
Completed gap analysis and implemented comprehensive HIPAA compliance program.
Our compliance team is available to discuss your specific requirements, review our certifications, or help you understand how we protect your data.
We typically respond to compliance inquiries within 2-4 hours.
compliance@caresuite.com
1-888-HIPAA-123
Request our compliance package
Last Updated: March 15, 2024 | Version 3.2
CareSuite maintains continuous compliance with all HIPAA rules and regulations. This page is reviewed and updated quarterly.