Skip to content

Compliance

What we hold ourselves to, and how you can check.

HIPAA and the SHIELD Act are the floor. This page says what is built, what is in progress, and whom to email when something is not right.

Effective September 18, 2026. Questions: hello@thecardinalgroup.org.

01HIPAA

The Cardinal Group LLC d/b/a CarePair Technologies handles protected health information as a business associate of the hospitals, care organizations, and senior living communities that use CarePair to send or receive information about their patients and residents. We sign a business associate agreement with each of them on request, and we have one in place with Amazon Web Services, which runs every part of the service that touches health information.

Safeguards as built:

  • Encryption in transit (TLS 1.2 or better) and at rest (database and file bucket under AWS KMS), with per-document and per-record data keys on top for documents and sensitive fields.
  • Role- and row-level authorization on every server action: a family sees its own case, a community sees only what was sent to it, a hospital sees the cases it referred.
  • An append-only audit log of every read and write of health information: who, what, which fields, when, from where.
  • Two-step sign-in for every staff, community, and partner login; 15-minute idle timeout for those sessions; a session list with revoke.
  • Minimum necessary by design: staged disclosure means financial details are collected only after a bed is offered and go to one community; physician forms pass through and are purged; Social Security and account numbers are relayed, never stored.
  • No health information in email subjects, text messages, logs, or analytics.
  • Written policies (information security, access control, incident response, vendor management, retention, acceptable use, change management, continuity, risk, training) with named owners and review dates.

02New York SHIELD Act

The SHIELD Act requires reasonable administrative, technical, and physical safeguards for New York residents' private information and notification when it is breached. The safeguards above are ours. Our incident response policy sets the clock: contain first, assess within 24 hours, notify affected people and the New York Attorney General as the Act requires, and the HHS Office for Civil Rights where HIPAA applies, each within the statutory deadline. We test the plan and keep a written record of every incident.

03SOC 2

SOC 2 is an auditor's report on our controls, not a self-declaration. We are building toward it: the ten policies are written, the controls they describe are the ones in the code and the AWS stack, and evidence collection follows. We expect a Type I report first and a Type II after the observation period. Until an auditor has signed, we say in progress, not certified. Hospital and enterprise partners can ask for our current control list and the evidence behind any item.

04Accessibility

We want everyone who cares for an older adult to be able to use CarePair, including people who use a screen reader, a keyboard alone, magnification, or voice control. Our target is WCAG 2.1 Level AA across the public site and the app: semantic structure, visible focus, sufficient contrast, labels on every control, one primary action per screen, and text that works at 200 percent zoom.

If you hit a barrier, email hello@thecardinalgroup.org with the page and what happened. We reply within five business days, fix what we can quickly, and give you another way to do the task in the meantime.

05Electronic signatures

Agreements in CarePair are signed by ticking the stated consents, typing your name, and pressing the button. We record the exact text signed, the signer's name, the date and time, and the network address, and we show the record to both sides. This satisfies the federal E-SIGN Act and New York's Electronic Signatures and Records Act. Paper copies are available on request, and consent to electronic records can be withdrawn as the Terms of Service describe.

06Reporting a security issue

If you find a vulnerability, email hello@thecardinalgroup.org with enough detail to reproduce it. We acknowledge within two business days, keep you informed, and credit you if you want. We do not run a bug bounty. Please do not access other people's information, run automated scanning against the production service, or disclose the issue publicly before we have fixed it.

07Vendors that run the service

Every outside service that touches CarePair data, and what each one sees:

  • Amazon Web Services (hosting, database, file storage, encryption keys, email through Amazon SES, text messages, secrets, logs): sees health information; covered by a business associate agreement; single region in the United States.
  • Cloudflare (DNS for trycarepair.com): sees domain name lookups only. The proxy is never enabled, so no application traffic passes through Cloudflare.
  • PostHog (product analytics, only if a key is configured): sees page views on the public site only, never on signed-in pages, and no health information.
  • Cal.com (booking for business calls on /book): sees the name, email, and chosen time of a business contact who books a call. Not used by families.
  • GitHub (source code and continuous integration): sees code and synthetic test data only, never real data.
  • Stripe (payments for Homeward memberships and from business customers, when enabled): takes the card on its own checkout page, so no card data touches our servers. Stripe receives only an email address, an opaque membership id and the plan; no names, no health details, no case data.

Related: Security · Privacy Policy · Terms of Service