Security & Trust

Last updated: July 10, 2026

CareCommand handles some of the most sensitive information a care facility holds — residents' health records, medication administration, incidents, and funds. For that protected health information (PHI), CareCommand acts as a Business Associateunder HIPAA and processes PHI only under a signed Business Associate Agreement (BAA) and the facility's instructions. This page describes, in plain terms, how we protect it.

How we protect your data

Encryption

Access control & tenant isolation

Audit trail

HIPAA & Business Associate Agreements

CareCommand operates as a HIPAA Business Associateand has implemented the administrative, physical, and technical safeguards described by the HIPAA Security Rule. (HIPAA has no government "certification" — any product that calls itself "HIPAA certified" is overstating. What actually matters is executed agreements and real, enforced safeguards, which we describe here and will document for your team or counsel on request.)

Secure development & change management

Infrastructure & resilience

Your data rights

Our SOC 2 program

We are building toward a SOC 2 examination and want to be precise about where we are, because the word gets overused. We are not yet SOC 2 certified. What we have done:

What remains before a report exists: engaging an independent auditor and running the observation period a SOC 2 Type II report requires. We're happy to share our control documentation and BAA with prospective facilities under NDA in the meantime.

Reporting a vulnerability

If you believe you've found a security issue, please email security@carecommand.online. We take reports seriously and will respond promptly. Please give us a reasonable chance to remediate before any public disclosure.


Questions from your team or your attorney? Our BAA and security policy documentation are available to prospective and current facilities on request. See also our Privacy Policy and Terms.