Overview
How we handle your patients' data.
ProbityCare stores protected health information for behavioral health and substance use treatment organizations. That means two overlapping regimes — HIPAA, and the stricter confidentiality rules for substance use records under 42 CFR Part 2 — and both are built into the product rather than written into a policy nobody reads.
This page is where we publish what is true today. Where a control is complete, it says so. Where an audit is underway, it says that instead. We would rather lose a deal to a vendor with a finished SOC 2 report than claim one we do not have.
Compliance
Compliance
Frameworks we are held to, and where each one currently stands.
Administrative, physical, and technical safeguards implemented. BAA executed before any PHI is loaded.
Consent-scoped disclosure controls for substance use disorder records, enforced at the record level.
Breach notification procedures and timelines documented and tested.
Audit engaged. The report is not yet available and we will publish it here when it is.
Third-party application testing scheduled. Results will be published as a summary report.
Under evaluation. We will not claim it until certification is complete.
Documents
Documents
Public documents download immediately. Private documents are released under a mutual NDA, usually within one business day.
Product security
Product security
Security controls your administrators operate themselves, inside the product.
Immutable activity log of every view, edit, signature, export, and permission change, retained seven years.
Permissions scoped by role, program, billing entity, and record section.
SAML SSO for organizations that require it.
Available on all accounts and enforceable at the organization level.
Configurable idle timeout and forced re-authentication for sensitive actions.
Customers can export their records in a usable format at any time, including at termination.
Data security
Data security
How records are protected while we hold them, and what happens when you leave.
TLS 1.2 or higher on all connections. HSTS enabled.
AES-256 on all stored data, including backups and file attachments.
Each customer's records are logically separated and scoped to their tenant.
Encrypted automated backups with point-in-time recovery. Restores are tested.
Retention configurable to your state and accreditation requirements.
Documented deletion process on termination, with written confirmation.
Access control
Access control
Who at ProbityCare can reach production data, and under what conditions.
Internal access to production is limited to the smallest set of staff required.
Internal access is reviewed on a scheduled basis and on every role change.
Access revoked as part of the documented departure checklist.
Administrators can produce a report of who can see what, for their own reviews.
Data privacy
Data privacy
Obligations specific to behavioral health records, including the ones HIPAA alone does not cover.
Executed with every covered entity before implementation begins.
Named recipient, purpose, scope, and expiration captured and enforced on disclosure.
Documented process and timelines consistent with HIPAA and HITECH.
Process for access, correction, and accounting-of-disclosures requests.
We do not sell, rent, or share customer data. Patient data is never used to train models.
Privacy questions and requests are handled by a named contact, not a queue.
Infrastructure
Infrastructure
Where the platform runs and how it is monitored.
United States regions only. Data does not leave the country without your written instruction.
Continuous uptime and performance monitoring with alerting.
Public status and incident history.
Production runs in a private network with restricted ingress.
Edge protection and rate limiting in front of the application.
Centralized infrastructure logs with automated alerting on anomalies.
Application security
Application security
How the software itself is built, reviewed, and released.
Peer review required on every change. No direct writes to production.
Automated scanning of third-party libraries with tracked remediation.
Report a vulnerability to Hello@probitycare.com. We respond and will not pursue good-faith researchers.
Documented release process with rollback, tested before production.
Corporate security
Corporate security
The controls that apply to our own team.
Performed on staff with access to production systems, where permitted by law.
Required at onboarding and annually, with completion recorded.
Company devices are encrypted, managed, and remotely wipeable.
Signed by every employee and contractor before access is granted.
Subprocessors
Subprocessors
Third parties that may process customer data, and what each one does. We post a notice on this page before adding any subprocessor that touches protected health information.
Policies
Policies
Written policies maintained by ProbityCare. Full text is available under NDA.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Reviewed annually and on material change.
Incident response
Incident response
What happens if something goes wrong, and how to tell us if you find something.
Documented plan with defined roles, severity levels, and communication steps.
Affected customers are contacted directly, within the timelines HIPAA requires.
Every incident gets a written review, and material ones are posted to this page.
Send findings to Hello@probitycare.com. We will acknowledge within two business days.
Business continuity
Business continuity
What happens if infrastructure fails, and how quickly you get back to a working chart.
Documented recovery objectives with restores tested on a schedule.
Backups are encrypted, access-controlled, and stored separately from production.
Multi-zone deployment so a single failure does not take the platform down.
Scheduled continuity exercises with documented outcomes.
Trust Center updates
Trust Center updates
Changes to our security posture, subprocessors, and compliance status, most recent first.
Trust Center published
This Trust Center replaces the ad-hoc security questionnaire process. Public documents are downloadable immediately; private documents are available under NDA.
SOC 2 Type II audit engaged
We have engaged an independent auditor for a SOC 2 Type II examination. We will publish the report here when the observation period closes. Until then we do not represent ourselves as SOC 2 certified.
Subprocessor list published
Our current subprocessors and the purpose of each are now listed on this page. We will post a notice here before adding any subprocessor that processes protected health information.
Security reviews, questionnaires, and BAA requests go to Hello@probitycare.com and are answered by a person, not a portal.
Report it to Hello@probitycare.com. We acknowledge within two business days and will not pursue good-faith research.
