Skip to main content

HIPAA safeguard design

45 CFR § 164 safeguards, carefully mapped

CareMAR provides technical features that can support a facility's safeguards. HIPAA compliance depends on the deployed configuration, agreements, policies, training, risk analysis, and day-to-day operation—not software alone.

What this page does not claim

This is not a certification, legal opinion, guarantee of survey results, or promise that every safeguard is automatic. It describes current product controls and names responsibilities that remain with the facility and its advisors.

Current product-control map

§ 164.308Administrative safeguards3 controls
§ 164.310Physical safeguards3 controls
§ 164.312Technical safeguards5 controls

Each line maps one safeguard category of 45 CFR § 164 to the controls documented below.

Administrative safeguards (§ 164.308)

  • Application roles distinguish facility administrator, nurse, and CNA permissions.
  • Audit events are recorded for covered application actions; facilities still own policy, workforce training, review cadence, and sanction procedures.
  • Feature flags and client configuration allow deployment-specific controls to be documented before use.

Physical safeguards (§ 164.310)

  • CareMAR uses AWS-managed infrastructure; the exact client account and responsibility boundary is confirmed during onboarding.
  • The application requires no facility-hosted server, while facilities remain responsible for workstation and device safeguards.
  • Browser auth tokens use sessionStorage, and the application applies a 15-minute client-side idle lock on shared-device sessions.

Technical safeguards (§ 164.312)

  • The primary DynamoDB table uses AWS-managed encryption; S3 document/report buckets use S3-managed encryption and block public access.
  • S3 buckets enforce SSL requests and application endpoints use HTTPS; no single-version TLS claim is made here.
  • Cognito supports optional authenticator-app TOTP MFA. SMS fallback is not configured, and MFA is not represented as mandatory for every current user.
  • Audit records are append-only at the audit service role, with update and delete denied.
  • Controlled-substance workflows include role and distinct-witness checks where that feature applies.

Business Associate Agreement

A suitable signed agreement and deployment review are required before CareMAR handles live PHI. BAA availability, parties, subcontractor terms, and current language must be confirmed during onboarding. This page is not a BAA, and W0 does not select or enable a legal form.

Incident notification

Notification duties and timelines depend on the incident, applicable law, and signed agreements. CareMAR does not publish an unverified shorter response promise or outside-counsel arrangement here. A facility should confirm the incident process and contacts before go-live.

Reports and survey preparation

CareMAR supports defined PDF and CSV report workflows and chronological audit records. Available fields and formats depend on the selected report. The current product does not promise an arbitrary complete-system export in both formats for every record and date window.

Review the underlying technical controls on the security page.

Compliance review questions

Email hello@caremar.us with subject “HIPAA review.” We will identify current reviewed materials and explicitly list any open agreement, policy, or control item.