← Back to Infini HealthCare

Data Practices & HIPAA Compliance

Our HIPAA posture

Infini HealthCare handles a subset of information that constitutes Protected Health Information (PHI) under 45 CFR § 160.103. We treat all PHI in accordance with the HIPAA Security Rule (administrative, physical, and technical safeguards) and the Privacy Rule (use and disclosure limitations).

Business Associate Agreements

We have executed (or are in process of executing) BAAs with the following subcontractors that may process PHI on our behalf:

VendorRoleStatus
Stripe, Inc.PaymentsBAA available
ResendTransactional emailBAA available (Pro plan)
MongoDB AtlasDatabaseBAA available
TwilioSMS (optional)BAA available
Apollo.ioAdmin lead searchNever receives PHI

Safeguards in place

  • Encryption in transit: TLS 1.2+ on every request; HSTS enforced
  • Encryption at rest: AES-256 via MongoDB Atlas + object storage encryption
  • Access controls: role-based (super_admin / coo / regional_manager / admin / agency / caregiver / family), least privilege, state-scoped for regional managers
  • Audit logging: every administrative action + PHI access is recorded with actor, IP, timestamp
  • Session management: JWT with expiring tokens, brute-force lockout, automatic session purge
  • Backups: nightly encrypted backups with 14-day rotation
  • Incident response: a documented breach-notification process with a 60-day maximum notification window per § 164.404

What we do NOT store

  • Full raw payment card numbers (handled by Stripe as PCI-DSS Level 1 processor)
  • Social Security Numbers of caregivers (except last-4 for 1099 reporting via Stripe Connect)
  • Medical diagnoses or lab results (unless a family voluntarily uploads them to a care plan)
  • Clinical notes from licensed providers

Your rights

Under HIPAA § 164.524, you have the right to access, inspect, and receive a copy of your PHI. Use Settings → Privacy → Export my data in your dashboard, or email privacy@careco24.com. We respond within 30 days.

Report a security concern

Please email security@careco24.com with details. We do not have a bug bounty at this time but we acknowledge every legitimate report and will not pursue legal action against good-faith researchers.

Executed BAAs and our full Security & Compliance package (SOC 2 report when available) are shared with enterprise customers under NDA. Contact compliance@careco24.com.

Press on me and ask me a question
Voice or text — I know the app inside out.