Security

HIPAA-oriented safeguards, without the marketing exaggeration

RaliCare supports each customer’s compliance programme with technical safeguards, clear responsibilities and honest language. Software alone does not make an organisation HIPAA compliant.

Role-based access

Care staff, supervisors, billing, administrators and read-only auditors each see only what they are authorised to.

Row-level security

Every private route resolves membership, role, facility access and object state server-side.

Auditable evidence

Corrections, approvals, exports and financial changes remain attributable with the original record preserved.

Minimum necessary

Sensitive information is never used as decoration or included in analytics payloads.

Encrypted transport & storage

Data is encrypted in transit and at rest, with secrets managed through the hosting platform.

Session hygiene

Idle sessions expire and re-authentication is required for sensitive actions.

Shared responsibility

RaliCare provides technical safeguards and audit surfaces. Customers remain responsible for workforce training, access reviews, appropriate use, and their organisational policies. We publish a HIPAA responsibility matrix and vendor register as part of onboarding.