Our Commitment to HIPAA Compliance
As a provider of care management software for assisted living facilities, we understand the critical importance of protecting Protected Health Information (PHI). LivingCare Pro maintains comprehensive administrative, physical, and technical safeguards to ensure HIPAA compliance.
We operate as a Business Associate under HIPAA and execute Business Associate Agreements (BAAs) with all customers who are Covered Entities or Business Associates themselves.
Administrative Safeguards
- Security Management Process: Regular risk assessments and security policy reviews
- Workforce Training: Mandatory HIPAA training for all employees
- Information Access Management: Need-to-know basis access controls
- Contingency Planning: Data backup, disaster recovery, and emergency mode procedures
- Evaluation: Regular assessments of security policies and procedures
Physical Safeguards
- Facility Access Controls: Data hosted in SOC 2 Type II certified facilities
- Workstation Security: Encrypted endpoints and secure access policies
- Device and Media Controls: Secure disposal and re-use procedures
Technical Safeguards
- Access Control: Unique user identification, automatic logoff, encryption/decryption
- Audit Controls: Comprehensive logging of all system activity
- Integrity Controls: Mechanisms to authenticate and validate data
- Transmission Security: End-to-end encryption for all data in transit
Business Associate Agreement
We provide a signed Business Associate Agreement (BAA) to all qualifying customers. Our BAA includes:
- Permitted uses and disclosures of PHI
- Safeguards to protect PHI
- Breach notification requirements
- Termination provisions
- Return or destruction of PHI upon termination
Contact us at compliance@livingcarepro.com to request a BAA.
Breach Notification
In the unlikely event of a data breach, we will:
- Notify affected customers within 24 hours of discovery
- Conduct a thorough investigation
- Provide detailed information about the breach
- Assist with notifications to affected individuals as required
- Implement measures to prevent future incidents
Your Responsibilities
While we provide a HIPAA-compliant platform, your organization also has responsibilities:
- Train your staff on HIPAA requirements and proper use of the system
- Implement appropriate access controls and user management
- Report any suspected security incidents immediately
- Maintain your own HIPAA compliance program
- Execute required agreements with your Business Associates
Third-Party Audits
We undergo regular third-party security audits and penetration testing to validate our security controls. Audit reports are available to customers under NDA upon request.
Questions?
For questions about our HIPAA compliance program, please contact:
- Privacy Officer: privacy@livingcarepro.com
- Security Officer: security@livingcarepro.com
- Phone: (800) 555-CARE