Security at CareSense
CareSense is trusted by healthcare organizations to collect and safeguard sensitive patient information. Security and privacy are foundational to how MedTrak, Inc. builds and operates the platform. This page provides an overview of the technical and organizational measures we use to protect customer and patient data.
Compliance
The CareSense platform is designed and operated to comply with the Health Insurance Portability and Accountability Act (HIPAA). We enter into Business Associate Agreements with our customers and maintain a security program aligned with the SOC 2 Trust Services Criteria (security, availability, and confidentiality). Our security policies, including this page and our Privacy Policy, are reviewed at least annually.
Infrastructure and Hosting
CareSense is hosted in Amazon Web Services (AWS) data centers located in the United States. AWS maintains industry-leading physical and environmental controls and holds certifications including SOC 1/2/3 and ISO 27001. Production systems are protected by firewalls and network access controls that block unauthorized access to our web servers and databases, and production environments are separated from development and testing environments.
Data Encryption
All data transmitted between users, patients, and the CareSense platform is encrypted in transit using TLS. Sensitive data is encrypted at rest within our hosting environment, and system credentials and secrets are stored in a managed secrets service with controlled access and rotation.
Access Control
Access to systems and data follows the principle of least privilege. Users receive unique credentials, and role-based access controls restrict what each user can see and do within the platform. Internal access to production systems and customer data is limited to authorized personnel who require it to deliver and support the Service, and access is reviewed periodically.
Monitoring and Logging
We log authentication activity and system events, including IP addresses and login attempts, and monitor for attempted security penetrations, technical problems, and unusual usage patterns. Current platform availability and incident history are published on our System Status page.
Secure Development
Application changes are version-controlled, peer-reviewed, and tested before release. Security considerations are part of our development process, and identified vulnerabilities are triaged and remediated based on severity.
Incident Response
We maintain an incident response process covering identification, containment, remediation, and communication. Security incidents affecting customer data are handled in accordance with HIPAA breach-notification requirements and our contractual commitments, and service-affecting incidents are posted to our System Status page.
Business Continuity
Production data is backed up on a regular schedule, and backups are protected with the same care as production systems. Recovery procedures are designed to restore the Service promptly in the event of a disruption.
Our People
All MedTrak employees complete training on HIPAA, privacy, and security practices, and are bound by confidentiality obligations. Sensitive information is protected through access controls, encryption, and secure workspace practices.
Reporting a Security Concern
If you believe you have discovered a vulnerability in CareSense or have a security question, please contact us at info@caresense.com. We ask that you report issues responsibly and refrain from testing the Service without prior written authorization.
Last Updated: August 1st, 2026