Compliance

HIPAA Compliance & BAA

Effective date: January 1, 2026 · BAA incorporated into Terms of Service

Karewel is Your HIPAA Business Associate

A Business Associate Agreement (BAA) is automatically in effect for all Karewel customers. By accepting our Terms of Service, you enter into a binding BAA with Karewel Technologies, Inc.. You do not need to request a separate BAA — it is already included.

1. HIPAA Overview

The Health Insurance Portability and Accountability Act (HIPAA), along with the HITECH Act, establishes national standards for protecting sensitive patient health information. HIPAA applies to:

  • Covered Entities: Healthcare providers (including RCFEs, SNFs, ARFs), health plans, and healthcare clearinghouses that create, receive, maintain, or transmit Protected Health Information (PHI)
  • Business Associates: Companies that create, receive, maintain, or transmit PHI on behalf of a Covered Entity — this includes Karewel

As an RCFE, SNF, ARF, or similar facility, you are a Covered Entity. When you use Karewel to store, manage, or process resident health information, Karewel becomes your Business Associate and is required by law to sign a Business Associate Agreement with you.

2. Business Associate Agreement (BAA)

The Karewel Business Associate Agreement is incorporated by reference into our Terms of Service. By creating a Karewel account and accepting the Terms of Service, you enter into a binding BAA with Karewel Technologies, Inc..

The BAA covers:

  • Permitted uses and disclosures of PHI by Karewel as Business Associate
  • Safeguards Karewel will implement to protect PHI
  • Breach notification obligations (within 60 days of discovery)
  • Sub-processor (sub-BA) arrangements
  • PHI return or destruction upon termination
  • Compliance with the HIPAA Privacy Rule (45 CFR Part 164, Subpart E)
  • Compliance with the HIPAA Security Rule (45 CFR Part 164, Subpart C)
  • Compliance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D)

If your compliance program requires a signed BAA on company letterhead (common for Joint Commission audits or state licensing reviews), contact legal@karewel.com to request an executed copy.

3. What PHI Does Karewel Handle?

Karewel processes the following categories of Protected Health Information on behalf of licensed facilities:

PHI CategoryExamples in KarewelEncryption
DemographicsResident name, DOB, address, phoneAES-256 at rest; TLS in transit
Diagnoses & ConditionsDiagnosis history, allergies, care plan conditionsAES-256 at rest; TLS in transit
MedicationsActive orders, MAR entries, refill historyAES-256 at rest; TLS in transit
Controlled SubstancesSchedule II–V counts, disposition logsAES-256 at rest; TLS in transit
Clinical NotesCare notes, incident reports, assessmentsAES-256 at rest; TLS in transit
Physician OrdersOrder entries, physician NPI, verbal order documentationAES-256 at rest; TLS in transit

Karewel does not process financial PHI (e.g., billing records submitted to health plans) or imaging data. If your use case requires these capabilities, contact our team.

4. Security Safeguards

Karewel implements the following administrative, physical, and technical safeguards required by the HIPAA Security Rule:

📋

Administrative Safeguards

  • Security Officer designation
  • Workforce training program
  • Risk assessment (annual)
  • Incident response procedures
  • BAAs or DPAs with sub-processors that handle PHI
  • Access authorization policies

🏢

Physical Safeguards

  • SOC 2 compliant data centers
  • Facility access controls
  • Workstation use policies
  • Device encryption requirements
  • Media disposal procedures

🔒

Technical Safeguards

  • AES-256 encryption at rest
  • TLS 1.2+ in transit
  • Role-based access control
  • MFA support
  • Comprehensive audit logging
  • Automatic session timeout

5. Breach Notification

In the event of a suspected or confirmed breach involving PHI, Karewel will:

  1. Notify your organization within 60 days of discovering the breach, or sooner if practicable. Notification will include: (a) a description of what happened; (b) the types of PHI involved; (c) steps individuals can take to protect themselves; (d) what Karewel is doing to investigate and mitigate the breach; and (e) contact information for questions.
  2. Cooperate with your breach assessment to determine whether the incident constitutes a reportable breach under HIPAA.
  3. Provide documentation to support your notification obligations to HHS and, if applicable, affected individuals.

As the Covered Entity, your organization is responsible for notifying affected individuals and the Department of Health and Human Services (HHS) in accordance with 45 CFR §164.404–414.

To report a suspected security incident, contact security@karewel.com immediately.

6. Sub-Business Associates

Karewel engages the following sub-processors that may handle PHI. Each has a signed Data Processing Agreement or BAA in place:

  • Railway: Managed PostgreSQL database hosting — PHI stored in encrypted PostgreSQL instances in US-based data centers. Authentication is handled first-party by Karewel (encrypted session tokens); no third-party identity provider receives credentials or PHI.
  • Vercel: Application hosting — Provides the compute environment; PHI transits in memory during a request but is not persistently stored by Vercel.
  • Resend: Transactional email delivery — Notification emails reference records by name and link; clinical detail is minimized.
  • Twilio: SMS notifications (optional add-on) — Alert messages are minimized to the minimum necessary.
  • Stripe: Payment processing — Billing data only; no PHI.
  • Sentry: Error monitoring — Configured to scrub PHI from error logs before transmission.
  • DeepSeek: AI processing for assistant and clinical-drafting features — Queries are de-identified before transmission; Karewel does not send directly identifiable PHI to DeepSeek.
  • Video visits: Family video calls run on the video provider configured for your deployment. Unless a Business Associate Agreement is in place with that provider, family video is treated as a non-clinical channel and participants are advised not to share detailed health information over it.

Karewel will notify customers of any material changes to sub-processor arrangements that could affect PHI handling.

7. Resident / Patient Rights

Under HIPAA, residents in care facilities have the right to:

  • Access their health records (right of access, 45 CFR §164.524)
  • Request amendment of their health records (45 CFR §164.526)
  • Receive an accounting of disclosures (45 CFR §164.528)
  • Request restrictions on uses and disclosures
  • Request confidential communications

These rights are exercised through the healthcare facility (Covered Entity), not directly through Karewel. Residents and family members should contact their care facility to submit HIPAA rights requests. Karewel will support the facility in fulfilling such requests upon request.

8. California-Specific Requirements

California has additional health data privacy laws that apply alongside HIPAA:

  • Confidentiality of Medical Information Act (CMIA):California Health & Safety Code §56 et seq. provides stronger protections than HIPAA in some areas. Karewel complies with CMIA requirements.
  • California Electronic Health Records Law: Karewel supports the documentation and retention requirements under California HSC §123111 for patient records.
  • Title 22 Documentation: Karewel is designed to support CDSS Title 22 documentation requirements for RCFEs, including MAR retention (3 years per §87468), incident report logs, and controlled substance documentation per DEA 21 CFR §1304.
  • RCFE Licensure: Karewel does not replace the CDSS licensing process. Facilities remain fully responsible for their own licensure and compliance with CDSS regulations.

9. Requesting a Signed BAA

While the Karewel BAA is automatically incorporated into your Terms of Service, some compliance programs (e.g., Joint Commission, state licensing audits, or your organization's legal team) may require a separately executed BAA document.

To request an executed BAA on company letterhead:

1Email legal@karewel.com with subject: "BAA Request – [Your Facility Name]"
2Include: your organization name, Karewel account email, and any specific BAA template requirements
3We will provide an executed BAA within 5 business days

10. HIPAA Contact

For HIPAA-related inquiries, breach reporting, or to request our BAA:

Karewel Technologies, Inc.
Attn: Privacy & Security Officer
Email: legal@karewel.com
Security incidents: security@karewel.com
Response SLA: 5 business days for BAA requests; 24 hours for security incidents