HIPAA posture and BAA availability for your engagement
The people you serve share sensitive things when they reach out for support. Chaperone is designed around a HIPAA-informed posture, with safeguards, role-based access, human accountability, and BAA availability for qualifying engagements, so the organizations we serve can extend support with confidence.
A buyer-level view of how we approach HIPAA, backed by formal notices.
This page explains our posture in plain language for review teams. The binding, formal HIPAA content lives in our published notice, which is linked from the footer and goes through legal review.
Safeguards across people, process, and technology
HIPAA is more than a checkbox. We treat it as administrative, physical, and technical safeguards working together, with a person accountable at every step.
Administrative safeguards
Documented policies, workforce training, and defined responsibilities for how protected health information is handled across the platform.
Technical safeguards
Encryption in transit and at rest, role-based access controls, and audit logging across sensitive actions and managed infrastructure.
Physical safeguards
Support runs on managed cloud infrastructure with facility-level controls handled by vetted providers under appropriate agreements.
Where Chaperone fits in your compliance picture
When Chaperone handles protected health information on behalf of a covered entity, that relationship is governed by a Business Associate Agreement (BAA). The structure below describes how we think about that role; the final, executable terms are confirmed through legal review.
- Business Associate Agreement available for qualifying engagements
- Defined permitted uses and disclosures of PHI
- Minimum-necessary access principles
- Subcontractor flow-down expectations
- Breach notification commitments
- Support for individual rights requests
Principles that guide protected information
A consistent set of principles shapes how protected health information moves through Chaperone, from a first conversation to ongoing support.
Data minimization
We aim to collect and retain only what support genuinely requires, reducing exposure by design.
Role-based access
People see only the information their role requires, with least-privilege permissions throughout.
Encryption everywhere
Information is encrypted in transit and at rest across the platform and our managed infrastructure.
Audit trails
Sensitive actions are logged so access and changes can be reviewed and accounted for.
Human accountability
Intelligent guidance assists with routing and summaries; a qualified person stays responsible for care decisions.
Defined retention
Retention and disposition follow documented schedules aligned to the purpose of the information.
Posture here, binding terms in the notice
This page is a structural, buyer-level overview to support your review. The formal HIPAA content (the language that governs how protected health information is handled) goes through legal review and is published as our HIPAA Notice, accessible from the footer of every page.
Need a BAA or HIPAA documentation for your review?
Bring your questionnaire and your timeline. We’ll walk your team through our HIPAA posture and get the right documentation into your diligence process.
