The page your compliance reviewer should read first.
No badges we can't evidence. No claims we can't survive a questionnaire on. Here is exactly how we handle protected health information.
BAA on every engagement
We execute a Business Associate Agreement before any work involving PHI begins, and we flow obligations down to any subprocessor with access.
Documented data flows
Every engagement produces a data-flow diagram showing where PHI lives, moves, and stops. It's a deliverable, not an afterthought.
Access control by default
Least-privilege access, per-person accounts, and audit logging on systems containing PHI. Access is granted per engagement and revoked at its end.
AI-specific controls
BAA-eligible model endpoints only for PHI paths, redaction before inference, and prompt logging with PHI stripped. Full approach →
Where does the team sit — and who can touch PHI?
Care Software Solutions is US-led from Austin, Texas, with an established engineering bench in Pakistan. We're direct about this because you'd find out anyway, and because it's manageable when it's designed for:
PHI-touching roles
PHI access is defined per engagement. When a client requires US-only access, offshore engineers work only with de-identified or synthetic data.
Contractual controls
All personnel with any PHI exposure are covered by BAA flow-down and confidentiality obligations, with access logged.
Your call
If your policy requires US-only PHI access, we structure the engagement that way and say so in the SOW.
What we claim — and only what we can evidence
We do not display certification badges without current evidence. Ask us for the controls, policies, and engagement-specific documentation your review requires.
Send us your vendor security questionnaire.
We confirm scope and turnaround when we receive it, then return a completed response on the agreed schedule.
Book a 30-minute call