Compliance

HIPAA Compliance & BAA

Effective date: January 1, 2026 · BAA incorporated into Terms of Service

CareOps is Your HIPAA Business Associate

A Business Associate Agreement (BAA) is automatically in effect for all CareOps customers. By accepting our Terms of Service, you enter into a binding BAA with CareOps Technologies, Inc.. You do not need to request a separate BAA — it is already included.

1. HIPAA Overview

The Health Insurance Portability and Accountability Act (HIPAA), along with the HITECH Act, establishes national standards for protecting sensitive patient health information. HIPAA applies to:

  • Covered Entities: Healthcare providers (including RCFEs, SNFs, ARFs), health plans, and healthcare clearinghouses that create, receive, maintain, or transmit Protected Health Information (PHI)
  • Business Associates: Companies that create, receive, maintain, or transmit PHI on behalf of a Covered Entity — this includes CareOps

As an RCFE, SNF, ARF, or similar facility, you are a Covered Entity. When you use CareOps to store, manage, or process resident health information, CareOps becomes your Business Associate and is required by law to sign a Business Associate Agreement with you.

2. Business Associate Agreement (BAA)

The CareOps Business Associate Agreement is incorporated by reference into our Terms of Service. By creating a CareOps account and accepting the Terms of Service, you enter into a binding BAA with CareOps Technologies, Inc..

The BAA covers:

  • Permitted uses and disclosures of PHI by CareOps as Business Associate
  • Safeguards CareOps will implement to protect PHI
  • Breach notification obligations (within 60 days of discovery)
  • Sub-processor (sub-BA) arrangements
  • PHI return or destruction upon termination
  • Compliance with the HIPAA Privacy Rule (45 CFR Part 164, Subpart E)
  • Compliance with the HIPAA Security Rule (45 CFR Part 164, Subpart C)
  • Compliance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D)

If your compliance program requires a signed BAA on company letterhead (common for Joint Commission audits or state licensing reviews), contact legal@careops.ai to request an executed copy.

3. What PHI Does CareOps Handle?

CareOps processes the following categories of Protected Health Information on behalf of licensed facilities:

PHI CategoryExamples in CareOpsEncryption
DemographicsResident name, DOB, address, phoneAES-256 at rest; TLS in transit
Diagnoses & ConditionsDiagnosis history, allergies, care plan conditionsAES-256 at rest; TLS in transit
MedicationsActive orders, MAR entries, refill historyAES-256 at rest; TLS in transit
Controlled SubstancesSchedule II–V counts, disposition logsAES-256 at rest; TLS in transit
Clinical NotesCare notes, incident reports, assessmentsAES-256 at rest; TLS in transit
Physician OrdersOrder entries, physician NPI, verbal order documentationAES-256 at rest; TLS in transit

CareOps does not process financial PHI (e.g., billing records submitted to health plans) or imaging data. If your use case requires these capabilities, contact our team.

4. Security Safeguards

CareOps implements the following administrative, physical, and technical safeguards required by the HIPAA Security Rule:

📋

Administrative Safeguards

  • Security Officer designation
  • Workforce training program
  • Risk assessment (annual)
  • Incident response procedures
  • BAAs with all sub-processors
  • Access authorization policies

🏢

Physical Safeguards

  • SOC 2 compliant data centers
  • Facility access controls
  • Workstation use policies
  • Device encryption requirements
  • Media disposal procedures

🔒

Technical Safeguards

  • AES-256 encryption at rest
  • TLS 1.2+ in transit
  • Role-based access control
  • MFA support
  • Comprehensive audit logging
  • Automatic session timeout

5. Breach Notification

In the event of a suspected or confirmed breach involving PHI, CareOps will:

  1. Notify your organization within 60 days of discovering the breach, or sooner if practicable. Notification will include: (a) a description of what happened; (b) the types of PHI involved; (c) steps individuals can take to protect themselves; (d) what CareOps is doing to investigate and mitigate the breach; and (e) contact information for questions.
  2. Cooperate with your breach assessment to determine whether the incident constitutes a reportable breach under HIPAA.
  3. Provide documentation to support your notification obligations to HHS and, if applicable, affected individuals.

As the Covered Entity, your organization is responsible for notifying affected individuals and the Department of Health and Human Services (HHS) in accordance with 45 CFR §164.404–414.

To report a suspected security incident, contact security@careops.ai immediately.

6. Sub-Business Associates

CareOps engages the following sub-processors that may handle PHI. Each has a signed Data Processing Agreement or BAA in place:

  • Supabase: Database hosting and authentication — PHI stored in encrypted PostgreSQL instances in US-based data centers
  • Railway: Application hosting — Provides the compute environment; PHI transits but is not persistently stored by Railway outside the database
  • Sentry: Error monitoring — Configured to scrub PHI from error logs before transmission
  • DeepSeek: AI processing for clinical features — Queries are anonymized before transmission; CareOps does not send directly identifiable PHI to DeepSeek

CareOps will notify customers of any material changes to sub-processor arrangements that could affect PHI handling.

7. Resident / Patient Rights

Under HIPAA, residents in care facilities have the right to:

  • Access their health records (right of access, 45 CFR §164.524)
  • Request amendment of their health records (45 CFR §164.526)
  • Receive an accounting of disclosures (45 CFR §164.528)
  • Request restrictions on uses and disclosures
  • Request confidential communications

These rights are exercised through the healthcare facility (Covered Entity), not directly through CareOps. Residents and family members should contact their care facility to submit HIPAA rights requests. CareOps will support the facility in fulfilling such requests upon request.

8. California-Specific Requirements

California has additional health data privacy laws that apply alongside HIPAA:

  • Confidentiality of Medical Information Act (CMIA):California Health & Safety Code §56 et seq. provides stronger protections than HIPAA in some areas. CareOps complies with CMIA requirements.
  • California Electronic Health Records Law: CareOps supports the documentation and retention requirements under California HSC §123111 for patient records.
  • Title 22 Documentation: CareOps is designed to support CDSS Title 22 documentation requirements for RCFEs, including MAR retention (3 years per §87468), incident report logs, and controlled substance documentation per DEA 21 CFR §1304.
  • RCFE Licensure: CareOps does not replace the CDSS licensing process. Facilities remain fully responsible for their own licensure and compliance with CDSS regulations.

9. Requesting a Signed BAA

While the CareOps BAA is automatically incorporated into your Terms of Service, some compliance programs (e.g., Joint Commission, state licensing audits, or your organization's legal team) may require a separately executed BAA document.

To request an executed BAA on company letterhead:

1Email legal@careops.ai with subject: "BAA Request – [Your Facility Name]"
2Include: your organization name, CareOps account email, and any specific BAA template requirements
3We will provide an executed BAA within 5 business days

10. HIPAA Contact

For HIPAA-related inquiries, breach reporting, or to request our BAA:

CareOps Technologies, Inc.
Attn: Privacy & Security Officer
Email: legal@careops.ai
Security incidents: security@careops.ai
Response SLA: 5 business days for BAA requests; 24 hours for security incidents