Privacy Policy
Last updated: July 2, 2026
CareCommand provides operations and compliance software to licensed assisted-living facilities, group homes, and their staff ("Customers"). This policy explains how we handle information in the CareCommand platform. For protected health information (PHI), CareCommand acts as a Business Associateof the Customer under HIPAA and processes PHI only per our Business Associate Agreement (BAA) and the Customer's instructions.
Information we process
- Account & staff data: names, work email, role, and authentication identifiers.
- Resident PHI (as a Business Associate): demographics, diagnoses, medications and administration records (MAR), vitals, care notes, incidents, and resident-fund/financial records — processed on the Customer's behalf.
- Operational data: schedules, tasks, documents, inventory, and compliance records.
- Technical data: log, device, and usage data, and an immutable audit trail of access to PHI.
How we use information
- To provide, secure, and support the platform.
- To maintain the audit trail and detect anomalous or unauthorized access (a HIPAA safeguard).
- We do not sell personal information or PHI, and we do not use PHI for advertising.
How we protect information
- Encryption in transit (TLS/HSTS) and at rest; application-layer encryption for stored credentials.
- Role-based access control, MFA for privileged roles, and automatic access termination on staff offboarding.
- An append-only audit log of PHI access, with anomaly detection and alerting.
- Vendor management: subprocessors that touch PHI operate under a BAA (see below).
Subprocessors
We use vetted subprocessors to run the service (cloud hosting, database, error monitoring, and — where enabled by the Customer — communications). Subprocessors that process PHI do so under a BAA. A current list is available to Customers on request.
Data retention
Customer and resident records are retained per the Customer's instructions and applicable state retention requirements (e.g., medication-administration and clinical records). Audit logs are retained for the period required by HIPAA. We provide deletion and export on request (see your rights below).
Your rights
Depending on your role and jurisdiction, you may request access to, correction of, a copy of, or deletion of personal information. For resident PHI, requests are directed through the Customer (the covered entity). Submit a request via the data-request form or by contacting us below; we respond within the timelines required by applicable law.
We do not sell personal information
We do not sell personal information, and we do not use resident PHI for marketing or advertising. Period.
Marketing outreach data
For business outreach to care providers, we use professional contact information from public sources (such as the federal NPPES provider registry and state business filings) and licensed business databases. Every marketing email includes one-click unsubscribe, and opt-outs are honored permanently. To have your business contact information removed from our outreach lists, email privacy@carecommand.online — we respond within 45 days.
Cookies
The signed-in application uses only essential cookies (sign-in sessions, security) and first-party analytics to understand product usage — no advertising or cross-site tracking cookies run inside the product, and PHI is never shared with advertising platforms.
Our public marketing pages (this website and campaign landing pages) may use advertising pixels from Meta and LinkedIn to measure our ads and show relevant ones to people who visited these pages. You can opt out through those platforms' ad settings or your browser's tracking controls.
Contact
Phone support: (561) 372-4600. Privacy questions or requests: privacy@carecommand.online. Security issues: see our security & trust page or email security@carecommand.online.
See also our Terms of Service.