Security and HIPAA at Case Log Pro
At Case Log Pro we take the security of Protected Health Information (PHI) seriously.
Encryption PHI is encrypted at rest using AES-256-GCM and in transit over HTTPS/TLS. We do not store or transmit PHI in plain text.
Access control Access is tied to authenticated users and sessions. We support optional app lock and biometrics on device. Session timeouts and secure logout help protect shared devices.
Audit logging PHI access may be logged with details such as who, what, when, and from where. Account-linked audit logs are retained while the account is active and deleted when the account is deleted.
Data retention and deletion We retain account-linked data while your account is active. Confirmed in-app deletion immediately and permanently removes account-linked server data and clears locally stored app data. We never sell your data.
Business Associate Agreements (BAAs) If you are a Covered Entity under HIPAA and will disclose PHI to us, a BAA may be required. Contact us at support@caselogpro.com to execute a BAA before using the Service with PHI.
For security or compliance questions, reach out anytime.