Skip to main content

Trust & data

Trust and safety for post-visit follow-up.

Careward is built for procedure practices that need clear patient follow-up without giving software clinical authority. Routine answers stay inside approved pathway content. Red flags and uncertainty go to the care team.

This page is maintained by Careward to describe current product behavior and shared responsibility — not an independent audit.

Verified controls

What an independent reviewer can ask us to evidence today.

SOC 2 Type II
Attestation dated November 2025.
BAA available
BAA-supported workflows are available for covered entities before PHI is processed.
Encryption
AES-256 at rest. TLS 1.3 in transit.
Authentication
MFA for practitioner logins. Azure AD SSO supported.
Role-based access
Front-desk, coordinator, and clinical-ops scopes.
No PHI in global training
Patient PHI is not used to train global models.

Human authority boundary

What Careward will and will not do without a person in the loop.

Careward sends
Careward may send approved routine answers, reminders, and check-ins.
Careward escalates
Careward escalates worsening symptoms, medication safety concerns, complaints, unclear questions, and out-of-scope messages.
Clinical staff decide
Clinical staff decide care actions, callbacks, appointments, documentation, and treatment.

Data movement

What goes in, what comes back, and the fallbacks when an integration is unavailable.

Data in
Patient name, phone, procedure code, discharge timestamp.
Data out
Episode Summary PDF to the patient chart on closure, where writeback is configured.
Permissions
Read-only demographics; write limited to post-op note or summary fields.
Fallback
Manual CSV upload if API latency or availability blocks sync.

Storage, retention, escalation design

How records are isolated, kept, and surfaced for review.

Isolation
Row-level isolation per practice; only enrolled team members can access records.
Retention
Per practice agreement and BAA; export and deletion on request.
Escalation triggers
Red-flag keywords, low AI confidence, two missed check-ins, urgent message.
AI rule
The AI never responds to an escalated message — that's reserved for your care team.

AI answers approved content. Humans review escalations.

The AI does not diagnose, prescribe, determine treatment urgency, or tell a patient not to seek care. If a message does not match approved pathway content with sufficient confidence, it routes to the escalation console for human review.

Designed for covered-entity review.

SOC 2 Type II attestation dated November 2025. BAA-supported workflows are available for covered entities before PHI is processed. Careward is not HIPAA certified. HIPAA is a regulatory framework; Careward supports covered-entity review through encryption, access controls, audit logging, BAA workflows, and human escalation boundaries. Your practice is responsible for using Careward consistent with your HIPAA obligations and other applicable laws.

Need a BAA? Email privacy@careward.co with "BAA request" in the subject.

Configured EHR/patient-portal hooks are confirmed per deployment. We do not publish vendor integration logos that have not been verified for healthcare workflow scope.