SECURITY & PRIVACY
Security and privacy are designed into the CareCueD architecture from the beginning.
CareCueD is built for healthcare environments where data sensitivity, accountability, and access control are not optional. The following describes our security design goals and principles.
CareCueD is designed with HIPAA-aligned privacy and security principles. Healthcare organizations remain responsible for configuring and operating CareCueD in accordance with their own legal, regulatory, privacy, security, and organizational requirements. CareCueD does not hold HIPAA certification — no such certification exists. A Business Associate Agreement (BAA) is available for qualifying organizations.
Role-Based Access Control
CareCueD enforces role-based access so that each user — resident, CNA, nurse, administrator, family member — sees only the information appropriate to their role. Access levels are configurable per facility and per user type. No single user has unrestricted access to all facility data by default.
Facility Separation
Each facility operates in a logically separated tenant environment. Data from one facility is not accessible to users of another facility. Tenant boundaries are enforced at the application and data layer.
Audit Logging
CareCueD maintains a timestamped log of system events including request submission, acknowledgment, escalation, completion, and status changes. These logs are designed to support internal accountability, quality review, and incident reconstruction. Administrators can review the sequence of events rather than reconstructing incidents from memory.
Encrypted Transmission
All data transmitted between CareCueD clients and servers is encrypted in transit using TLS. CareCueD does not transmit resident data over unencrypted channels.
Authentication & Session Controls
CareCueD supports secure authentication workflows including session management, access token controls, and configurable session timeout. Facilities can configure authentication requirements appropriate to their environment and policy.
Least-Privilege Design
CareCueD is designed on a least-privilege principle: users and system components are granted only the access necessary to perform their function. Elevated access requires explicit authorization.
Family Portal Access Controls
Family portal access is controlled per facility policy, resident authorization, and applicable privacy requirements. Facilities determine what information is visible to family members and under what conditions. CareCueD does not provide unrestricted access to protected health information.
Business Associate Agreement
A signed Business Associate Agreement (BAA) is available for qualifying healthcare organizations before go-live. The BAA documents the responsibilities of each party with respect to protected health information handled through CareCueD.
AI & Clinical Use Disclaimer
Domonique 2.0 is CareCueD's intelligent workflow and conversational assistance layer. It supports request categorization, urgency identification, routing, documentation assistance, and escalation monitoring. Domonique 2.0 supports — but does not replace — professional clinical judgment, emergency procedures, or facility policy. CareCueD does not independently diagnose medical conditions and does not replace nurses, CNAs, physicians, administrators, or clinical decision-making.
Emergency Services Disclaimer
CareCueD is a communication, workflow, documentation, and escalation platform. It is not a substitute for emergency services, professional medical assessment, or a facility's required emergency-response procedures. In any life-threatening situation, call 911 and follow your facility's emergency protocols.