HIPAA notice & security posture

KinBridge Health AI is designed under HIPAA Security Rule safeguards. This page summarizes how we protect protected health information (PHI); for the binding contract terms see our Privacy Policy and Terms & Conditions.

Administrative safeguards

  • Signed Business Associate Agreements (BAAs) with every subprocessor that touches PHI (LLM, OCR, transcription, email, storage).
  • Least-privilege role model in every workspace — primary caregiver, caregiver, aide, family, viewer.
  • Access audit trail persisted for six years for every PHI read + write.

Technical safeguards

  • TLS 1.2+ in transit, AES-256 at rest on both database and object storage.
  • JWT session tokens revocable per-device; sessions terminate immediately on caregiver revoke.
  • Support agents cannot view a patient's name, DOB, or address until they complete a caller-verification challenge for that specific family (30 min window, 5-attempt lockout).
  • Per-patient siloing — a paid aide only sees the loved one they're assigned to.

Physical safeguards

  • All infrastructure hosted in SOC-2-audited US data centers.
  • Mobile audio recordings stay on-device unless the caregiver explicitly shares them.

Breach notification

In the rare event of a PHI breach, KinBridge Health AI will notify affected individuals within 60 days per 45 CFR §164.404, as well as the U.S. Department of Health and Human Services. Contact privacy@kinbridgehealth.com with any questions.