Trust & data
Trust and safety for post-visit follow-up.
Careward is built for procedure practices that need clear patient follow-up without giving software clinical authority. Routine answers stay inside approved pathway content. Red flags and uncertainty go to the care team.
This page is maintained by Careward to describe current product behavior and shared responsibility — not an independent audit.
Verified controls
What an independent reviewer can ask us to evidence today.
- SOC 2 Type II
- Attestation dated November 2025.
- BAA available
- BAA-supported workflows are available for covered entities before PHI is processed.
- Encryption
- AES-256 at rest. TLS 1.3 in transit.
- Authentication
- MFA for practitioner logins. Azure AD SSO supported.
- Role-based access
- Front-desk, coordinator, and clinical-ops scopes.
- No PHI in global training
- Patient PHI is not used to train global models.
Human authority boundary
What Careward will and will not do without a person in the loop.
- Careward sends
- Careward may send approved routine answers, reminders, and check-ins.
- Careward escalates
- Careward escalates worsening symptoms, medication safety concerns, complaints, unclear questions, and out-of-scope messages.
- Clinical staff decide
- Clinical staff decide care actions, callbacks, appointments, documentation, and treatment.
Data movement
What goes in, what comes back, and the fallbacks when an integration is unavailable.
- Data in
- Patient name, phone, procedure code, discharge timestamp.
- Data out
- Episode Summary PDF to the patient chart on closure, where writeback is configured.
- Permissions
- Read-only demographics; write limited to post-op note or summary fields.
- Fallback
- Manual CSV upload if API latency or availability blocks sync.
Storage, retention, escalation design
How records are isolated, kept, and surfaced for review.
- Isolation
- Row-level isolation per practice; only enrolled team members can access records.
- Retention
- Per practice agreement and BAA; export and deletion on request.
- Escalation triggers
- Red-flag keywords, low AI confidence, two missed check-ins, urgent message.
- AI rule
- The AI never responds to an escalated message — that's reserved for your care team.
AI answers approved content. Humans review escalations.
The AI does not diagnose, prescribe, determine treatment urgency, or tell a patient not to seek care. If a message does not match approved pathway content with sufficient confidence, it routes to the escalation console for human review.
Designed for covered-entity review.
SOC 2 Type II attestation dated November 2025. BAA-supported workflows are available for covered entities before PHI is processed. Careward is not HIPAA certified. HIPAA is a regulatory framework; Careward supports covered-entity review through encryption, access controls, audit logging, BAA workflows, and human escalation boundaries. Your practice is responsible for using Careward consistent with your HIPAA obligations and other applicable laws.
Need a BAA? Email privacy@careward.co with "BAA request" in the subject.
Configured EHR/patient-portal hooks are confirmed per deployment. We do not publish vendor integration logos that have not been verified for healthcare workflow scope.