PrimeCare Systems
Security & Compliance

HIPAA-grade homecare.
Built that way from day one.

AES-256 encryption, strict tenant isolation, BAAs with every vendor, and an immutable PHI access log. Hand this page to your compliance officer with confidence.

🔐
AES-256 at rest
SSNs, clinical notes, and sensitive client identifiers are encrypted with AES-256 field-level encryption before they touch the database.
🛡️
Strict tenant isolation
Every database query is rewritten to include the caller's tenant_id. 19 automated security tests verify no agency can ever see another agency's data.
🔑
Per-tenant API keys
Each agency gets a unique X-API-Key for integrations. Keys are revocable, scoped, and never logged in plaintext.
📜
Immutable PHI audit log
Every SMS view, export, and bulk operation writes one row to the HIPAA access log. Tenant admins read their own; super-admins see everything.
🤝
BAAs with every vendor
Twilio (SMS), Brevo (email), MongoDB Atlas (database), Cloudflare (CDN) all under signed BAAs. Stripe handles payments only — no PHI.
🌐
TLS 1.2+ in transit
All traffic terminates on Cloudflare with TLS 1.2+ and HSTS. HTTP requests are 301'd to HTTPS at the edge.

HIPAA Compliance Posture

PrimeCare Systems LLC acts as a Business Associate under HIPAA when handling Protected Health Information (PHI) on behalf of our customer agencies (Covered Entities). Every agency that signs up signs our BAA electronically as part of trial activation.

SafeguardHow we satisfy itHIPAA citation
Access ControlRole-based + tenant-scoped; per-user passwords with bcrypt + JWT sessions; admin 2FA available.§164.312(a)(1)
Audit ControlsImmutable hipaa_access_log captures every PHI view, export, SMS send, and bulk operation.§164.312(b)
IntegrityAppend-only audit log; database-level constraints; ETag/version checks on update endpoints.§164.312(c)(1)
Transmission SecurityTLS 1.2+ end-to-end, HSTS preload, modern cipher suites enforced at Cloudflare edge.§164.312(e)(1)
Encryption at restAES-256 field-level encryption for SSNs and clinical notes; full disk encryption on MongoDB Atlas.§164.312(a)(2)(iv)
BackupAutomated daily snapshots, 30-day retention, geographically redundant.§164.308(a)(7)(ii)(A)

Subprocessors

We use the following third-party services to deliver the platform. Each has signed a HIPAA Business Associate Agreement with PrimeCare, or, where they do not handle PHI, an SOC 2 / equivalent attestation.

Twilio
SMS delivery (A2P 10DLC)
🟢 HIPAA BAA signed · Handles PHI
Brevo
Transactional email delivery
🟢 HIPAA BAA signed · Handles PHI
MongoDB Atlas
Database hosting & backups
🟢 HIPAA BAA signed · Handles PHI
Cloudflare
CDN, WAF, TLS termination
🟢 HIPAA BAA signed · Handles PHI
Stripe
Payment processing (no PHI)
⚪ No PHI access
Emergent
Application hosting infrastructure
🟢 HIPAA BAA signed · Handles PHI

Breach Notification & Incident Response

If we become aware of a security incident or breach of unsecured PHI, we notify affected agencies within 30 days (faster when feasible), including the nature of the incident, the data involved, mitigating actions taken, and recommendations for downstream notification to individuals where required.

Report a suspected vulnerability or incident: security@primecaresystems.com

Legal Documents

📄 Business Associate Agreement (PDF)📄 Terms of Service (PDF)View BAA onlineView Terms online
© 2026 PrimeCare Systems LLC · Built for HIPAA · Home