This page is a plain-language overview of how ProbityCare Solutions Inc. protects Protected Health Information. It is not the contract. The binding commitments are in our Business Associate Agreement, which every customer organization enters into with us.
1Our role under HIPAA
Your organization is the covered entity. It holds the direct relationship with the patient, owns the medical record, and issues the Notice of Privacy Practices.
ProbityCare is a business associate. We create, receive, maintain, and transmit PHI on your behalf in order to provide intake, clinical documentation, billing, revenue cycle, and workforce functions. We use PHI only to deliver those services, as permitted by the BAA, or as required by law.
Four commitments that do not change
- We never sell PHI and never accept remuneration in exchange for it.
- We never use PHI for marketing, fundraising, or advertising, ours or anyone else’s.
- We never use PHI to train external AI models.
- Your records remain yours, and you can export them at any time.
3Administrative safeguards
- Security management process. A documented risk analysis is performed at least annually and after any significant change to the environment, with a tracked risk management plan.
- Assigned security responsibility. Named Security Officer and Privacy Officer accountable for the program.
- Written policies. Policies and procedures covering privacy, security, access management, incident response, sanctions, device and media controls, and contingency planning, reviewed at least annually.
- Business associate management. A signed BAA is in place with every subcontractor that touches PHI, imposing the same restrictions we accept.
- Information system activity review. Regular review of access reports, audit logs, and security incident tracking.
4Technical safeguards
| Control | How we implement it |
|---|---|
| Encryption in transit | TLS 1.2 or higher for all connections, with modern cipher suites and HSTS. |
| Encryption at rest | AES-256 for databases, object storage, and backups. |
| Access control | Unique named accounts, mandatory multi-factor authentication, role-based permissions, and row-level authorization so records are scoped to the organization and program that owns them. |
| Audit controls | Immutable, timestamped logging of record access, modification, export, and administrative changes, searchable by user, patient, and date range. |
| Integrity | Versioned clinical documentation with amendment history, signature attribution, and no destructive edits to signed notes. |
| Authentication | Password policy aligned to NIST SP 800-63B, credential-stuffing protection, rate limiting, and automatic session timeout. |
| Transmission security | Secure internal messaging, encrypted claim and lab exchange, and no PHI in email or SMS notifications. |
5Physical safeguards
The platform runs on cloud infrastructure in United States data centers operated by providers who maintain SOC 2 Type II and ISO 27001 certification, with 24/7 staffing, biometric access control, video surveillance, and environmental protection. We do not operate our own data centers.
- All PHI is stored and processed within the United States. We do not transfer PHI offshore.
- Workstation security. Company devices are encrypted, centrally managed, screen-locked, and remotely wipeable.
- Media disposal. Decommissioned media is cryptographically erased or destroyed by the infrastructure provider under certificate.
6Substance use records under 42 C.F.R. Part 2
Stricter than HIPAA
Records from a federally assisted substance use disorder program carry protections beyond HIPAA. Most disclosures require written patient consent, redisclosure is prohibited without further consent, and the records generally cannot be used in legal proceedings against the patient without a court order.
The platform is built with these rules in mind:
- Consent capture and expiry tracking, so a disclosure cannot be made under a lapsed consent.
- Program-level segmentation, so Part 2 records are visible only to staff with a role that permits it.
- The required prohibition-on-redisclosure notice attached to qualifying disclosures.
- Disclosure logging that supports the accounting obligations introduced by the CARES Act alignment of Part 2 with HIPAA.
Determining whether your program is subject to Part 2, and obtaining valid consent, remains your organization’s responsibility. We provide the mechanism; you make the determination.
7Minimum necessary
We limit our request, use, and disclosure of PHI to the minimum necessary to accomplish the purpose. In practice that means engineering and support staff do not have standing access to customer records.
- Production access requires an approved, time-boxed request tied to a specific support ticket or incident.
- Every access is logged, attributed, and reviewed.
- Non-production environments use synthetic or de-identified data. Production PHI is never copied into development or test systems.
8Workforce and training
- Background checks before hire, to the extent permitted by law.
- Signed confidentiality agreements covering PHI for all personnel and contractors.
- HIPAA and security awareness training at onboarding and annually, with role-specific training for engineering and support, plus phishing simulation.
- A documented sanction policy, up to and including termination, for violations.
- Access is revoked as part of the offboarding checklist on the last day of employment.
9Subprocessors
We use a deliberately small set of subprocessors. Each one that handles PHI has signed a business associate agreement imposing the same obligations we accept, and each is restricted to United States regions.
| Subprocessor | Function | PHI | Location |
|---|---|---|---|
| Supabase | Primary database, authentication, and file storage for the platform | Yes — BAA in place | United States |
| Vercel | Application hosting and content delivery | Yes — BAA in place | United States |
| Google (Analytics) | Aggregate traffic measurement on the public marketing website only | No | United States |
| Microsoft (Clarity) | Heatmaps and session replay on the public marketing website only | No | United States |
Optional integrations you enable
The admin portal lets you switch on integrations such as clearinghouse claim submission, laboratory results, e-prescribing, communications, and payment processing. These run under vendor accounts that ProbityCare holds rather than credentials you supply, so any of them that handles PHI is our subprocessor: we sign the downstream business associate agreement, and the vendor is bound by the same obligations listed above. Enabling an integration authorizes that specific disclosure; leaving it off means no data is shared with that vendor.
Current integration list
Because the available integrations change as we add them, we maintain the current list — including which vendor backs each one and whether it receives PHI — outside this page. Email security@probitycare.com for the current version, or check the integrations screen in your admin portal, where each connector names its vendor before you enable it.
If you would rather contract with a vendor directly under your own agreement, tell us and we will confirm whether that integration supports customer-supplied credentials. We will give customers at least 30 days notice before adding a subprocessor that will handle PHI. To receive those notices, email security@probitycare.com.
10Analytics and PHI never mix
Website analytics is a common source of accidental PHI disclosure across the industry — typically when a tracking script is left running on an authenticated page and captures a URL, form field, or on-screen record.
How we prevent it
- Google Analytics and Microsoft Clarity load only on the public marketing website, never on any authenticated route of the platform.
- Both are blocked until a visitor opts in through the consent banner.
- Clarity runs with text input masking enabled, so typed content is not recorded.
- Advertising identifiers, Google Signals, and remarketing are disabled, so no audience can be built from visits.
- Application URLs never contain patient identifiers in query strings that could leak through a referrer header.
Full detail on what these tools collect is in our Privacy Policy.
11Breach and incident response
We maintain a documented, tested incident response plan. Our contractual notification commitments are:
Our report will include, to the extent known:
- What happened, and the date of the incident and of discovery.
- The categories of PHI involved and the individuals affected.
- What we have done to investigate, mitigate, and contain the incident.
- Steps we recommend you take, and what we are doing to prevent recurrence.
You remain responsible for the notifications required under the HIPAA Breach Notification Rule to affected individuals, the Secretary of Health and Human Services, and where applicable the media. We will provide the information and cooperation you need to make them.
Suspect an incident? Contact security@probitycare.com immediately. We monitor this address continuously.
12Supporting patient rights
Patients exercise their HIPAA rights through your organization, not through us. Where we hold PHI in a Designated Record Set on your behalf, we support you within these timeframes:
13Backup, recovery, and continuity
- Automated encrypted backups with point-in-time recovery.
- Geographically separated backup storage within the United States.
- Restore procedures tested at least annually.
- A documented contingency plan covering data backup, disaster recovery, and emergency mode operation so clinical staff retain access to records during a disruption.
14Assessments and audits
- Annual HIPAA Security Rule risk analysis with a tracked remediation plan.
- Annual third-party penetration test of the application and infrastructure.
- Continuous dependency and vulnerability scanning with defined remediation windows.
- Annual review of all policies, procedures, and subprocessor agreements.
Customers and prospective customers under NDA may request our current security documentation package, including risk analysis summary, penetration test attestation, and policy index, by emailing security@probitycare.com.
15Requesting a Business Associate Agreement
A BAA is required before any PHI enters the platform. Our standard Business Associate Agreement is entered into when your account is created, and it covers the great majority of customers without modification.
If your organization requires its own BAA form, or negotiated terms, email legal@probitycare.com with the document and we will review it. We will not accept PHI until a BAA is executed.
16Report a concern
Security and privacy contacts
ProbityCare Solutions Inc.2125 Biscayne Blvd, Ste 303Miami, FL 33137
Security incidents: security@probitycare.com
Privacy questions: privacy@probitycare.com
Legal and BAAs: legal@probitycare.com
Security researchers are welcome to report vulnerabilities to security@probitycare.com. Please do not access, modify, or exfiltrate any data that is not your own, and give us a reasonable opportunity to remediate before disclosure. We will not pursue action against researchers who follow these guidelines in good faith.
You may also file a complaint with the HHS Office for Civil Rights. We do not retaliate against anyone who files a complaint.
17Revision history
- Version 3.0. First publication of this overview as a standalone page, separated from the legal text of the BAA. Adds the shared responsibility model, the control inventory, 42 C.F.R. Part 2 handling, the subprocessor list with a 30-day change notice, the analytics separation policy, and the assessment schedule.
