Compliance

HIPAA Compliance & BAA

Effective date: January 1, 2026 · BAA incorporated into Terms of Service

Kare Wel is Your HIPAA Business Associate

A Business Associate Agreement (BAA) is automatically in effect for all Kare Wel customers. By accepting our Terms of Service, you enter into a binding BAA with Kare Wel Technologies, Inc.. You do not need to request a separate BAA — it is already included.

1. HIPAA Overview

The Health Insurance Portability and Accountability Act (HIPAA), along with the HITECH Act, establishes national standards for protecting sensitive patient health information. HIPAA applies to:

  • Covered Entities: Healthcare providers (including RCFEs, SNFs, ARFs), health plans, and healthcare clearinghouses that create, receive, maintain, or transmit Protected Health Information (PHI)
  • Business Associates: Companies that create, receive, maintain, or transmit PHI on behalf of a Covered Entity — this includes Kare Wel

As an RCFE, SNF, ARF, or similar facility, you are a Covered Entity. When you use Kare Wel to store, manage, or process resident health information, Kare Wel becomes your Business Associate and is required by law to sign a Business Associate Agreement with you.

2. Business Associate Agreement (BAA)

The Kare Wel Business Associate Agreement is incorporated by reference into our Terms of Service. By creating a Kare Wel account and accepting the Terms of Service, you enter into a binding BAA with Kare Wel Technologies, Inc..

The BAA covers:

  • Permitted uses and disclosures of PHI by Kare Wel as Business Associate
  • Safeguards Kare Wel will implement to protect PHI
  • Breach notification obligations (within 60 days of discovery)
  • Sub-processor (sub-BA) arrangements
  • PHI return or destruction upon termination
  • Compliance with the HIPAA Privacy Rule (45 CFR Part 164, Subpart E)
  • Compliance with the HIPAA Security Rule (45 CFR Part 164, Subpart C)
  • Compliance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D)

If your compliance program requires a signed BAA on company letterhead (common for Joint Commission audits or state licensing reviews), contact legal@karewel.com to request an executed copy.

3. What PHI Does Kare Wel Handle?

Kare Wel processes the following categories of Protected Health Information on behalf of licensed facilities:

PHI CategoryExamples in Kare WelEncryption
DemographicsResident name, DOB, address, phoneAES-256 at rest; TLS in transit
Diagnoses & ConditionsDiagnosis history, allergies, care plan conditionsAES-256 at rest; TLS in transit
MedicationsActive orders, MAR entries, refill historyAES-256 at rest; TLS in transit
Controlled SubstancesSchedule II–V counts, disposition logsAES-256 at rest; TLS in transit
Clinical NotesCare notes, incident reports, assessmentsAES-256 at rest; TLS in transit
Physician OrdersOrder entries, physician NPI, verbal order documentationAES-256 at rest; TLS in transit

Kare Wel does not process financial PHI (e.g., billing records submitted to health plans) or imaging data. If your use case requires these capabilities, contact our team.

4. Security Safeguards

Kare Wel implements the following administrative, physical, and technical safeguards required by the HIPAA Security Rule:

📋

Administrative Safeguards

  • Security Officer designation
  • Workforce training program
  • Risk assessment (annual)
  • Incident response procedures
  • BAAs with all sub-processors
  • Access authorization policies

🏢

Physical Safeguards

  • SOC 2 compliant data centers
  • Facility access controls
  • Workstation use policies
  • Device encryption requirements
  • Media disposal procedures

🔒

Technical Safeguards

  • AES-256 encryption at rest
  • TLS 1.2+ in transit
  • Role-based access control
  • MFA support
  • Comprehensive audit logging
  • Automatic session timeout

5. Breach Notification

In the event of a suspected or confirmed breach involving PHI, Kare Wel will:

  1. Notify your organization within 60 days of discovering the breach, or sooner if practicable. Notification will include: (a) a description of what happened; (b) the types of PHI involved; (c) steps individuals can take to protect themselves; (d) what Kare Wel is doing to investigate and mitigate the breach; and (e) contact information for questions.
  2. Cooperate with your breach assessment to determine whether the incident constitutes a reportable breach under HIPAA.
  3. Provide documentation to support your notification obligations to HHS and, if applicable, affected individuals.

As the Covered Entity, your organization is responsible for notifying affected individuals and the Department of Health and Human Services (HHS) in accordance with 45 CFR §164.404–414.

To report a suspected security incident, contact security@karewel.com immediately.

6. Sub-Business Associates

Kare Wel engages the following sub-processors that may handle PHI. Each has a signed Data Processing Agreement or BAA in place:

  • Supabase: Database hosting and authentication — PHI stored in encrypted PostgreSQL instances in US-based data centers
  • Railway: Application hosting — Provides the compute environment; PHI transits but is not persistently stored by Railway outside the database
  • Sentry: Error monitoring — Configured to scrub PHI from error logs before transmission
  • DeepSeek: AI processing for clinical features — Queries are anonymized before transmission; Kare Wel does not send directly identifiable PHI to DeepSeek

Kare Wel will notify customers of any material changes to sub-processor arrangements that could affect PHI handling.

7. Resident / Patient Rights

Under HIPAA, residents in care facilities have the right to:

  • Access their health records (right of access, 45 CFR §164.524)
  • Request amendment of their health records (45 CFR §164.526)
  • Receive an accounting of disclosures (45 CFR §164.528)
  • Request restrictions on uses and disclosures
  • Request confidential communications

These rights are exercised through the healthcare facility (Covered Entity), not directly through Kare Wel. Residents and family members should contact their care facility to submit HIPAA rights requests. Kare Wel will support the facility in fulfilling such requests upon request.

8. California-Specific Requirements

California has additional health data privacy laws that apply alongside HIPAA:

  • Confidentiality of Medical Information Act (CMIA):California Health & Safety Code §56 et seq. provides stronger protections than HIPAA in some areas. Kare Wel complies with CMIA requirements.
  • California Electronic Health Records Law: Kare Wel supports the documentation and retention requirements under California HSC §123111 for patient records.
  • Title 22 Documentation: Kare Wel is designed to support CDSS Title 22 documentation requirements for RCFEs, including MAR retention (3 years per §87468), incident report logs, and controlled substance documentation per DEA 21 CFR §1304.
  • RCFE Licensure: Kare Wel does not replace the CDSS licensing process. Facilities remain fully responsible for their own licensure and compliance with CDSS regulations.

9. Requesting a Signed BAA

While the Kare Wel BAA is automatically incorporated into your Terms of Service, some compliance programs (e.g., Joint Commission, state licensing audits, or your organization's legal team) may require a separately executed BAA document.

To request an executed BAA on company letterhead:

1Email legal@karewel.com with subject: "BAA Request – [Your Facility Name]"
2Include: your organization name, Kare Wel account email, and any specific BAA template requirements
3We will provide an executed BAA within 5 business days

10. HIPAA Contact

For HIPAA-related inquiries, breach reporting, or to request our BAA:

Kare Wel Technologies, Inc.
Attn: Privacy & Security Officer
Email: legal@karewel.com
Security incidents: security@karewel.com
Response SLA: 5 business days for BAA requests; 24 hours for security incidents