HIPAA notice & security posture
KinBridge Health AI is designed under HIPAA Security Rule safeguards. This page summarizes how we protect protected health information (PHI); for the binding contract terms see our Privacy Policy and Terms & Conditions.
Administrative safeguards
- Signed Business Associate Agreements (BAAs) with every subprocessor that touches PHI (LLM, OCR, transcription, email, storage).
- Least-privilege role model in every workspace — primary caregiver, caregiver, aide, family, viewer.
- Access audit trail persisted for six years for every PHI read + write.
Technical safeguards
- TLS 1.2+ in transit, AES-256 at rest on both database and object storage.
- JWT session tokens revocable per-device; sessions terminate immediately on caregiver revoke.
- Support agents cannot view a patient's name, DOB, or address until they complete a caller-verification challenge for that specific family (30 min window, 5-attempt lockout).
- Per-patient siloing — a paid aide only sees the loved one they're assigned to.
Physical safeguards
- All infrastructure hosted in SOC-2-audited US data centers.
- Mobile audio recordings stay on-device unless the caregiver explicitly shares them.
Breach notification
In the rare event of a PHI breach, KinBridge Health AI will notify affected individuals within 60 days per 45 CFR §164.404, as well as the U.S. Department of Health and Human Services. Contact privacy@kinbridgehealth.com with any questions.