Security & HIPAA Readiness
MDS Command is built for SNF compliance teams. We follow HIPAA-aligned practices.
Infrastructure
Built on Lovable Cloud (AWS-hosted). A SOC 2 Type I report for the hosting platform is available upon request under NDA for surveyor / compliance review. We do not publish the report publicly.
Technical safeguards
- Encryption in transit: TLS 1.2+
- Encryption at rest: AES-256
- Facility data isolation via row-level security — each facility accesses only its own data
- Role-based access control: CNA / LPN / RN / IP / DON / Administrator
- Multi-factor authentication (MFA) available for IP/DON and admin roles
- Automatic logoff after 15 minutes of inactivity
- Passwords require 12+ characters
Administrative safeguards
- Immutable audit logs retained 6 years per CMS record retention guidance
- Business Associate Agreement (BAA) available to covered entities
- Workforce access on a least-privilege basis
- Breach notification procedures documented in our BAA and Terms
- Data return / destruction within 30 days of termination upon request
Data use
We do not use PHI for marketing. De-identified, aggregate data is used for case studies and product improvement only with explicit written authorization.
Request documents
For a copy of our BAA or to request our security questionnaire, contact your account representative or compliance contact.
This page describes our security practices and does not create a legal guarantee.