Built for data you'd rather not have to think about
Medicaid pre-screening handles income, household composition, and health-adjacent details from people at vulnerable moments. Here is — in plain language — how the platform protects that data, who can see it, and where the platform's role deliberately stops.
HIPAA safeguards, stated honestly
The platform is built with HIPAA's administrative, physical, and technical safeguards in mind: access control, audit trails, encryption, and data-minimization defaults described below. We're equally direct about what we don't claim — there is no such thing as a "HIPAA certification", and any vendor claiming one is overstating. What we offer instead is specific, verifiable controls, and we'll gladly walk your security or compliance team through each of them, including signing a Business Associate Agreement where the relationship requires one.
Six controls that do the heavy lifting
Every item below is a working feature of the platform today — not a roadmap entry.
Encryption of sensitive data
Screening involves exactly the kind of information that deserves care: names, phone numbers, household income, dates of birth. Sensitive personal fields are encrypted at rest in the database — not just the disk underneath it — so a copy of the raw storage doesn't expose patient answers. All traffic between browsers, phones, and the platform travels over encrypted connections.
Audit logging on every sensitive action
Who viewed a lead, who listened to a recording, who changed a screening rule, who exported a report — each of these writes an immutable audit entry recording the actor, the action, the affected record, the timestamp, and the originating IP address.
The log is append-only by design: there is no interface, for any role, that edits or deletes audit history. When your compliance team asks "who accessed this record?", the answer is a filtered search, not a forensic project.
Role-based access control
Access follows job function. Capabilities like viewing leads, listening to recordings, editing flows, managing users, and reading audit logs are discrete permissions grouped into roles you define. An outreach agent, a reviewer, and an administrator each see a different platform — and permission checks are enforced on the server for every request, not just hidden in the interface.
Recording access controls
Call recordings are among the most sensitive artifacts the platform holds, so they get their own permission — having access to a lead does not imply access to its audio. Playback and download URLs are short-lived and signed rather than public links, and every listen and download is individually audit-logged.
Configurable data retention
Different organizations operate under different retention obligations, so retention is a setting, not a constant. Your administrators choose how long call recordings and screening data are kept; when the window passes, expired records are cleaned up automatically and the cleanup itself is logged. Keeping data forever is a choice you make deliberately — never a default you inherited.
Consent, TCPA, and do-not-call handling
Phone outreach lives under real rules, and the platform treats them as first-class features. Callers are told a call may be recorded and asked for consent before recording begins; consent language is configurable to match your counsel's requirements, and the consent outcome is stored with the call.
A built-in do-not-call list is honored across the platform, and a patient's request to stop contact is recorded and enforced. Consent settings live in one place, so your policy is applied uniformly rather than depending on individual staff remembering it.
Estimates, not determinations
This bears stating as an explicit commitment rather than fine print: the platform provides eligibility estimates to help organizations prioritize outreach and review. Official Medicaid eligibility determinations are made exclusively by the state Medicaid agency. The platform never files applications, never approves or denies coverage, and every screening result passes through a human reviewer before any follow-up action is taken. Our product copy, patient-facing scripts, and result messages are all written to preserve that line.
Bring your security questionnaire
Procurement in this space rightly involves security review. We're set up for that conversation: we can walk your team through the access model, the audit log, the encryption approach, and retention behavior on a live system, and we respond to security questionnaires as part of every evaluation. Contact us to start that review, or request a demo and ask the hard questions there.
Data belongs to your organization. Screening data is scoped per organization, exportable through built-in reports, and removable on request — including full deletion at the end of an engagement.
Put our answers in front of your security team
We'd rather field the tough compliance questions in the first meeting than the last one.