Security details
The standard we hold ourselves to, and the controls behind it.
The Privacy and security page explains our protections in plain words. This page is the technical side: the yardstick we measure against, and the safeguard each protection relates to.
Our standard
HIPAA doesn’t cover us. We use it as our yardstick anyway.
HIPAA is the federal law that protects the health records held by most doctors, hospitals and health insurers, and by the companies working for them. Lenaya Health isn’t one of those: we work for you, not for a doctor or an insurer, so HIPAA doesn’t apply to us.
We didn’t think that was a good reason to do less. So we use HIPAA’s Security Rule — the part that says how health information must be protected — as the yardstick for how we build and run Lenaya. The table below names the HIPAA safeguard each of our protections relates to.
We don’t call ourselves “HIPAA compliant” or “HIPAA certified.” There is no official HIPAA certification, and a badge suggesting that HIPAA covers us would mislead you. The laws that do apply to us include the Federal Trade Commission’s Health Breach Notification Rule and state health-privacy laws such as Washington’s My Health My Data Act.
The controls
Each protection, and the safeguard it relates to.
| Protection | What it means | Related HIPAA safeguard |
|---|---|---|
| You control your Care Circle | Family, friends and caregivers can see your visits only if they are invited into your Care Circle. You choose whether each person can only view your visits or can also record visits and add documents for you, and you can change that, or remove them, at any time. | Access control |
| No password to steal | You sign in with your Google account, so we never create or store a password for you. On iPhone, your sign-in is kept in the phone’s secure Keychain, locked to that one phone. In a web browser, it is cleared when you close the tab. | Authentication |
| Encrypted on the way and where we keep it | Everything travels between your device and our servers over encrypted connections. Once uploaded, your recordings, transcripts, summaries and documents are encrypted where we store them, too. | Transmission security & encryption |
| Kept off the open internet | Your records are kept in a database and file storage that are closed to general access from the open internet. The Lenaya app connects to them over a private network. | Access control |
| A security log | Sign-ins, failed sign-in attempts and other important events on your account are recorded, and we keep that log for six years. | Audit controls |
| Visit notifications never say what was said | When a visit is ready, the notification says just that. Your visit details stay inside the app, behind your sign-in. | Minimum necessary (a HIPAA principle, not a safeguard) |
Behind the scenes
We put it in writing.
HIPAA expects more than good software. It expects someone to be accountable, and a plan for when things go wrong. We keep these in writing:
- A named person responsible for security, accountable for every decision about protecting your information.
- A written risk analysis of what could go wrong and what we do about it.
- A list of the companies that handle your information, what each one receives, and the contract that covers it.
- A plan for the unexpected. We keep a written plan for handling security problems, including how we would contact you if one ever affected your information.
Related HIPAA safeguards · Administrative
Questions about your privacy?
Read the full policy, or write to us.