Security you can verify. Status we don't inflate.
Most vendor "compliance" pages are a wall of badges. This one tells you exactly what's implemented, what's in progress, and what's still ahead — because you're the one signing the BAA.
How patient data is protected.
Encrypted everywhere
TLS in transit. AES-256 at rest, including AES-256-GCM message encryption and KMS-managed keys for document storage.
Per-agency data isolation
Every agency gets its own isolated clinical data store. Every query in the application layer is scoped to your agency.
Minimum-necessary access
Role-based and relationship-based access control: staff see the patients they're assigned to care for, per HIPAA's minimum-necessary principle.
MFA & session controls
TOTP multi-factor authentication with backup codes, account lockout, and configurable session timeout with warning.
Tamper-resistant audit trail
Every PHI read and write is logged. Audit and security logs are written to write-once storage and retained for 7 years.
Write-once document storage
PHI documents are stored with server-side KMS encryption, PHI classification tags, and write-once immutability.
Zero-PHI notifications
Outbound email never contains PHI — notifications link back into the authenticated platform instead.
BAA on every plan
A Business Associate Agreement is available on all plans, including Starter. It's a HIPAA requirement, not an upsell.
Where we stand, in writing.
Updated as our engineering and certification work progresses. If a vendor won't show you a table like this, ask why.
| Area | Status | Detail |
|---|---|---|
| HIPAA security safeguards | Implemented | Access control, MFA, encryption in transit and at rest, audit logging with 7-year retention, session controls, and BAA availability. |
| OASIS-E1 assessments | Implemented | Full OASIS-E1 capture with validation and iQIES export package generation. |
| PDGM & HH PPS claims (837I) | Implemented | 30-day period management and 837I generation with validation rules from CMS Pub. 100-04 Ch. 10. Claim transmission runs through your clearinghouse connection. |
| Notice of Admission (NOA) | Implemented | NOA lifecycle tracking with timely-filing visibility and late-filing exception documentation. |
| Electronic Visit Verification | Implemented | All six federal EVV data elements captured; exports for Sandata, HHAeXchange, and generic formats. State-specific aggregator adapters roll out per state. |
| X12 EDI transactions | Implemented | Eligibility (270/271), prior authorization (278), and claims/remittance (837/835) via clearinghouse integration — Availity live, additional clearinghouses ready. |
| FHIR R4 interoperability | Implemented | FHIR R4 resource API backed by per-agency Google Cloud Healthcare stores. US Core profile alignment in progress. |
| ONC Health IT Certification | In progress | Working toward ONC Health IT Certification. Privacy & security criteria and the FHIR R4 foundation are complete; standardized API certification testing is ahead of us. We will publish results as they happen. |
| Quality measures reporting | In progress | The measure-computation framework is built; we're aligning measure definitions with current CMS HH QRP specifications before we call it done. |
| SOC 2 Type II | Roadmap | Planned once our control environment reaches the maturity an audit deserves. We'd rather earn it than rush it. |
Have a security questionnaire or need specifics for your compliance review? Email contact@ariecare.com — we answer those directly.
Bring your compliance officer.
We'll walk through access control, audit trails, and the BAA together — before you sign anything.
