Trust centerUpdated August 27, 2026

Security and HIPAA overview

HeyHomeCare is designed for sensitive home care operations. This overview describes current engineering practices; signed customer agreements and security exhibits contain the binding commitments for a deployment.

Access and tenant isolation

Authenticated access is scoped to the customer organization. Application data access is tenant-filtered, privileged operations are role-controlled, and administrative activity is logged for investigation and audit support.

Encryption and credentials

Transport encryption protects data in transit. Stored integration credentials use authenticated encryption, and secrets are kept outside application source. Production access follows least-privilege practices.

HIPAA and BAAs

HeyHomeCare is designed for HIPAA-regulated workflows. A customer BAA and the required subprocessor agreements must be in place before production PHI is allowed to flow. Logs use PHI-aware redaction, and product workflows are designed around minimum-necessary access.

Monitoring and incident response

Operational events, integration failures, and access activity are logged and monitored. Incident procedures cover triage, containment, recovery, documentation, and customer notification obligations defined by contract and applicable law.

Security review

Customers can request architecture details, a current subprocessor and BAA-status review, and available security documentation during procurement. Contact hello@line.care.