Enterprise Security built for
healthcare-grade compliance

CareSphere protects resident and staff data with end-to-end encryption, immutable audit trails, and controls designed for alignment with HIPAA and PHIPA environments.

✓ HIPAA Aligned ✓ PHIPA Aligned ✓ AWS BAA Signed ✓ TLS 1.2+ In Transit ✓ AES-256 At Rest ✓ Immutable Audit Logs
📊

Regulatory Alignment Status

Current alignment across regulatory frameworks

HIPAA — Health Insurance Portability and Accountability Act
All 18 PHI identifiers encrypted; BAA signed with AWS; audit logging enabled; 6-year retention (US jurisdictions)
ALIGNED
PHIPA — Personal Health Information Protection Act (Ontario)
10-year retention; consent management; minimum-necessary access; breach notification procedures in place
ALIGNED
AWS Business Associate Agreement (BAA)
Signed for Aurora RDS, Cognito, S3, KMS, Secrets Manager, and CloudWatch Logs
SIGNED
Encryption in Transit
TLS 1.2+ enforced on all API endpoints, database connections, and IoT device communication
ACTIVE
Penetration Testing
Annual third-party penetration test; results available under NDA upon request
ANNUAL
✉️

Security questions?

Our security team is available for compliance reviews, BAA requests, and penetration test reports.

security@spiritify.ai