Trust center

Security you can verify. Status we don't inflate.

Most vendor "compliance" pages are a wall of badges. This one tells you exactly what's implemented, what's in progress, and what's still ahead — because you're the one signing the BAA.

Architecture

How patient data is protected.

Encryption

Encrypted everywhere

TLS in transit. AES-256 at rest, including AES-256-GCM message encryption and KMS-managed keys for document storage.

Isolation

Per-agency data isolation

Every agency gets its own isolated clinical data store. Every query in the application layer is scoped to your agency.

Access

Minimum-necessary access

Role-based and relationship-based access control: staff see the patients they're assigned to care for, per HIPAA's minimum-necessary principle.

Identity

MFA & session controls

TOTP multi-factor authentication with backup codes, account lockout, and configurable session timeout with warning.

Audit

Tamper-resistant audit trail

Every PHI read and write is logged. Audit and security logs are written to write-once storage and retained for 7 years.

Documents

Write-once document storage

PHI documents are stored with server-side KMS encryption, PHI classification tags, and write-once immutability.

Email

Zero-PHI notifications

Outbound email never contains PHI — notifications link back into the authenticated platform instead.

BAA

BAA on every plan

A Business Associate Agreement is available on all plans, including Starter. It's a HIPAA requirement, not an upsell.

Compliance status

Where we stand, in writing.

Updated as our engineering and certification work progresses. If a vendor won't show you a table like this, ask why.

Area Status Detail
HIPAA security safeguards Implemented Access control, MFA, encryption in transit and at rest, audit logging with 7-year retention, session controls, and BAA availability.
OASIS-E1 assessments Implemented Full OASIS-E1 capture with validation and iQIES export package generation.
PDGM & HH PPS claims (837I) Implemented 30-day period management and 837I generation with validation rules from CMS Pub. 100-04 Ch. 10. Claim transmission runs through your clearinghouse connection.
Notice of Admission (NOA) Implemented NOA lifecycle tracking with timely-filing visibility and late-filing exception documentation.
Electronic Visit Verification Implemented All six federal EVV data elements captured; exports for Sandata, HHAeXchange, and generic formats. State-specific aggregator adapters roll out per state.
X12 EDI transactions Implemented Eligibility (270/271), prior authorization (278), and claims/remittance (837/835) via clearinghouse integration — Availity live, additional clearinghouses ready.
FHIR R4 interoperability Implemented FHIR R4 resource API backed by per-agency Google Cloud Healthcare stores. US Core profile alignment in progress.
ONC Health IT Certification In progress Working toward ONC Health IT Certification. Privacy & security criteria and the FHIR R4 foundation are complete; standardized API certification testing is ahead of us. We will publish results as they happen.
Quality measures reporting In progress The measure-computation framework is built; we're aligning measure definitions with current CMS HH QRP specifications before we call it done.
SOC 2 Type II Roadmap Planned once our control environment reaches the maturity an audit deserves. We'd rather earn it than rush it.

Have a security questionnaire or need specifics for your compliance review? Email contact@ariecare.com — we answer those directly.

Bring your compliance officer.

We'll walk through access control, audit trails, and the BAA together — before you sign anything.