Last updated · May 2026
HIPAA Compliance
HIPAA-Conscious Platform
1. Our Commitment
Carelynk is designed from the ground up with HIPAA compliance in mind. We understand that RCFE operators handle sensitive resident health information and take our responsibilities as a technology partner seriously.
2. Business Associate Agreement (BAA)
Carelynk enters into a Business Associate Agreement (BAA) with all covered entity customers. Contact us at hello@carelynk.io to execute a BAA before going live.
3. Technical Safeguards
- End-to-end HTTPS encryption for all data in transit
- AES-256 encryption for data at rest
- Role-based access controls — staff only see what they need for their role
- Automatic session timeouts
- Audit logs of all data access and changes
- No PHI included in email notifications (login to view)
4. Administrative Safeguards
- Staff access provisioned by facility administrator
- Regular access reviews recommended
- Incident response procedures in place
- Employee training on HIPAA obligations
5. Physical Safeguards
- Data hosted on SOC 2 compliant infrastructure (Supabase)
- No physical access to servers by Carelynk staff
6. What We Don't Do
- We do not sell or share PHI with third parties
- We do not include PHI in email notifications
- We do not use resident data for advertising
- We do not access your facility data without authorization
7. Reporting a HIPAA Concern
If you believe there has been a breach or HIPAA violation, contact us immediately at hello@carelynk.io or call (800) XXX-XXXX.
8. Execute a BAA
Ready to get your BAA?
Contact our compliance team to execute your Business Associate Agreement before going live with Carelynk.