HIPAA Compliance You Can Count On
WaiverCarePro is architected from the ground up with HIPAA Privacy and Security Rules in mind โ protecting every piece of PHI your agency handles.
Administrative, Technical & Physical Safeguards
๐
Technical Safeguards
- โAES-256 encryption for all PHI at rest
- โTLS 1.3 enforced for all data in transit
- โSecure JWT authentication (30-min access tokens, 7-day refresh)
- โAPI rate limiting and request validation
- โSQL injection and XSS prevention throughout
๐
Administrative Safeguards
- โRole-based access control (RBAC) โ 6 roles with least-privilege
- โFull audit logging on all PHI access and modifications
- โMulti-factor authentication (MFA) support
- โTenant isolation โ data never crosses between agencies
- โUser activity monitoring and session management
๐ข
Physical Safeguards
- โHosted on Render infrastructure (SOC 2 Type II certified data centers)
- โPostgreSQL 16 with encrypted volumes
- โAutomated daily backups with point-in-time recovery
- โNo PHI stored on developer workstations
๐
Organizational Safeguards
- โBusiness Associate Agreement (BAA) available for Enterprise customers
- โStaff security awareness training documentation
- โIncident response plan and breach notification procedures
- โPrivacy policy and data retention policies in compliance with HIPAA
EVV Compliance โ 21st Century Cures Act
All Medicaid HCBS providers are required to use Electronic Visit Verification. WaiverCarePro's EVV meets federal and state requirements.
โ21st Century Cures Act compliant EVV implementation
โGPS coordinates captured and stored at clock-in/out
โGeofence validation with configurable radius per patient
โException flagging for missing GPS, early/late clock-in, and service mismatches
โVisit verification records maintained for Medicaid audit trail
โState EVV aggregator export support (Enterprise)
Complete Audit Trail
Every action taken on PHI โ create, read, update, delete โ is logged with user identity, timestamp, tenant, and change summary. Audit logs are immutable and retained per HIPAA requirements.
# Sample audit log entry
{
ย "timestamp": "2026-03-05T14:32:10Z",
ย "userId": "usr_abc123",
ย "tenantId": "tnt_xyz789",
ย "action": "UPDATE",
ย "entity": "patient",
ย "entityId": "pat_def456",
ย "changes": { dob: '...' }
}
Need a Business Associate Agreement (BAA)?
BAAs are available for all Enterprise plan customers. Contact our sales team to get started.
Contact Sales โ