Back to Home
Security & Compliance
Attorney review draft — not final
This page is provided for transparency during counsel review. It is not legal advice, not an offer to contract, and not evidence of HIPAA compliance or regulatory certification. Executed agreements control for paying customers.
Shift Warden LLC d/b/a Clinic Warden is built with security at every layer. Our platform is designed so your clinic's data stays protected while keeping compliance simple.
HIPAA-Aligned Security Controls
- Clinical Compliance uses internal client identifiers (CL-####), not patient names
- Intake Operations collects minimum necessary contact/referral data, which may include PHI
- Your EHR remains the clinical system of record
- Compliance metadata and audit trails — not clinical note content
Encryption
- TLS 1.2+ for all data in transit
- AES-256 encryption for data at rest
- Bcrypt password hashing with salting
Access Controls
- Role-based access (admin, supervisor, clinician)
- Tenant-isolated data access
- Session management with automatic expiry
- API key authentication with granular permissions
Audit Logging
- Append-only audit trail for privileged actions
- Every action timestamped and attributed
- Exportable logs for compliance verification
- Hash-chain integrity on audit rows (where enabled)
Infrastructure
- Hosted on Vercel (US East)
- Database on Supabase (AWS)
- Daily automated backups
- Multi-AZ redundancy
Incident Response
- Continuous security incident monitoring
- Breach notification procedures in place
- Regular security assessments
Compliance Documents
Review our legal and compliance documentation for full details on how Shift Warden LLC d/b/a Clinic Warden protects your data.
Request a Business Associate Agreement
If your organization requires a BAA for HIPAA compliance, Shift Warden LLC d/b/a Clinic Warden is ready to execute one. Reach out to our legal team to get started.
Contact founder@clinicwarden.com