Health information, held with care.
Tend is built for HIPAA from the ground up. The same care we bring to a patient on the phone, we bring to their data.
The safeguards under every call.
Encryption everywhere
PHI is encrypted in transit with TLS and at rest with AES-256. Call audio and transcripts are protected the same way.
Least-privilege access
Access to health information is scoped, logged, and reviewed. People see only what their role requires.
Audit logging
Every access and every escalation is recorded, so you can see who saw what and when.
Isolated by customer
Your data lives in your tenant boundary. Nothing crosses to another customer, ever.
Your data, your call
You can export or delete patient data on request. Retention windows are set with you.
SSO and provisioning
Single sign-on, SCIM provisioning, and role-based access on system plans.
A signed BAA on every paid plan.
HIPAA ready
Business Associate Agreement standard for all customers.
We act as your Business Associate
When Tend handles protected health information on your behalf, we do so under a Business Associate Agreement that spells out permitted uses, safeguards, breach notification, and your rights to audit and to delete.
Minimum necessary, always
Tend collects and uses only the information it needs to make a follow-up call and to write a summary. It does not compile profiles or use PHI for anything outside your engagement.
Breach notification
If a breach affecting your data were ever to occur, we notify you promptly and work the response with you, consistent with HIPAA timelines and your agreement.
Subprocessors under agreement
Any vendor that could touch PHI is under a written agreement with equivalent protections. We keep a current list and give notice of material changes.
Safety is a security property too.
The safest design choice is also an honest one. Tend tells patients what it is, never pretends to be a clinician, and never gives medical advice. Urgent red flags trigger an immediate handoff to your team and, when appropriate, a prompt to call 911. A person is always in the loop on an escalation.
Where we are, plainly stated.
We follow SOC 2 aligned practices and are pursuing formal attestation as we grow. We are glad to walk your security team through our controls, share our documentation, and complete your review. For anything about PHI, a BAA, or a questionnaire, write to security@tendcareai.com.
Bring your security review.
We will meet it with documentation, a BAA, and straight answers.