Back to Home
Security & Compliance
Attorney review draft — not final
This page is provided for transparency during counsel review. It is not legal advice, not an offer to contract, and not evidence of HIPAA compliance or regulatory certification. Executed agreements control for paying customers.
Shift Warden LLC d/b/a ClinicWarden is built with security at every layer. Our platform is designed so your clinic's data stays protected while keeping compliance simple.
HIPAA-Aligned Security Controls
- Clinical Compliance uses internal client identifiers (CL-####), not patient names
- Intake Operations collects minimum necessary contact/referral data, which may include PHI
- Your EHR remains the clinical system of record
- Compliance metadata and audit trails — not clinical note content
Encryption
- TLS 1.2+ for all data in transit
- AES-256 encryption for data at rest
- Bcrypt password hashing with salting
Access Controls
- Role-based access (admin, supervisor, clinician)
- Row Level Security enforced at the database
- Session management with automatic expiry
- API key authentication with granular permissions
Audit Logging
- Append-only audit trail for privileged actions
- Every action timestamped and attributed
- Exportable logs for compliance verification
- Hash-chain integrity on audit rows (where enabled)
Infrastructure
- Hosted on Vercel (US East)
- Database on Supabase (AWS)
- Daily automated backups
- Multi-AZ redundancy
Incident Response
- Continuous security incident monitoring
- Breach notification procedures in place
- Regular security assessments
Compliance Documents
Review our legal and compliance documentation for full details on how Shift Warden LLC d/b/a ClinicWarden protects your data.
Request a Business Associate Agreement
If your organization requires a BAA for HIPAA compliance, Shift Warden LLC d/b/a ClinicWarden is ready to execute one. Reach out to our legal team to get started.
Contact founder@clinicwarden.com