Security at PredictiCare
Home care runs on trust. This page describes, plainly, how the platform protects the information agencies put in it.
Encryption
All traffic to and from the platform is encrypted in transit with TLS. Data is encrypted at rest by our cloud provider, and identifying client and caregiver fields carry an additional layer of application-level field encryption on top of that.
Tokenized records
Client records are referenced by opaque tokens rather than identity. What a user can resolve from a token is governed by their role and scope.
Role-based access
Every role, from super admin to family member, is scoped by permission, office, and agency. Users see exactly their scope and nothing more, enforced server-side on every request.
Session controls
Sessions end after a short idle period and carry a hard maximum lifetime. Locking an account revokes its active sessions. Multi-factor authentication (TOTP and SMS) is built into the platform and staged for activation.
Hosting
PredictiCare runs on Google Cloud in the United States, on managed infrastructure with automated patching, private database networking, and monitored budgets and logs.
Auditability
Administrative and clinical activity is captured in an audit trail so agencies can answer who did what, and when.
Business Associate Agreements are available for customer agencies. We follow applicable breach-notification law. To report a suspected vulnerability or ask a security question, write to hello@predicticare.health.