Security & HIPAA Readiness

MDS Command is built for SNF compliance teams. We follow HIPAA-aligned practices.

Infrastructure

Built on Lovable Cloud (AWS-hosted). A SOC 2 Type I report for the hosting platform is available upon request under NDA for surveyor / compliance review. We do not publish the report publicly.

Technical safeguards

  • Encryption in transit: TLS 1.2+
  • Encryption at rest: AES-256
  • Facility data isolation via row-level security — each facility accesses only its own data
  • Role-based access control: CNA / LPN / RN / IP / DON / Administrator
  • Multi-factor authentication (MFA) available for IP/DON and admin roles
  • Automatic logoff after 15 minutes of inactivity
  • Passwords require 12+ characters

Administrative safeguards

  • Immutable audit logs retained 6 years per CMS record retention guidance
  • Business Associate Agreement (BAA) available to covered entities
  • Workforce access on a least-privilege basis
  • Breach notification procedures documented in our BAA and Terms
  • Data return / destruction within 30 days of termination upon request

Data use

We do not use PHI for marketing. De-identified, aggregate data is used for case studies and product improvement only with explicit written authorization.

Request documents

For a copy of our BAA or to request our security questionnaire, contact your account representative or compliance contact.

This page describes our security practices and does not create a legal guarantee.