While BedMatch is not currently required to be a HIPAA-covered entity, we have proactively designed HIPAA-grade privacy and security safeguards into every layer of our platform — because your family's sensitive information deserves the highest standard of protection.
BedMatch handles sensitive information about seniors, their health needs, care preferences, and family circumstances. Even though our platform may not fall under the strict regulatory definition of a HIPAA-covered entity or business associate, we believe that the nature of the data we handle demands the same level of care and protection that HIPAA requires.
Rather than waiting for regulatory requirements to catch up, we've embedded HIPAA-grade safeguards from day one. Our security architecture was designed with healthcare data standards in mind from the very first line of code.
Families trust us with deeply personal information about their loved ones. Care providers share operational data through our platform. That trust is sacred, and we protect it with the same rigor that HIPAA demands of hospitals and insurers.
As BedMatch grows and our role in the care placement ecosystem expands, we are positioned to achieve full HIPAA compliance seamlessly — because the infrastructure, policies, and practices are already in place.
Following the HIPAA Security Rule framework, BedMatch implements comprehensive safeguards across all three categories: administrative, physical, and technical. These work together to create a layered defense for your data.
BedMatch collects and processes several categories of sensitive information to provide accurate care matching. Every piece of data is treated with the same level of protection regardless of its classification.
BedMatch is committed to transparency and user empowerment. Consistent with the principles outlined in the HIPAA Privacy Rule and applicable state privacy laws, we provide you with meaningful control over your personal information.
Right to Access
Request a copy of all personal information we hold about you or your loved one at any time.
Right to Correction
Request corrections to any inaccurate or incomplete information in your account.
Right to Deletion
Request that we delete your personal data, subject to legal retention requirements.
Right to Restrict Processing
Limit how we use your data for specific purposes, including marketing communications.
Right to Data Portability
Receive your data in a structured, commonly used format for transfer to another service.
Right to Be Informed
Receive clear notice about what data we collect, how we use it, and who we share it with.
Submit a Request
Email [email protected] or call (888) 450-8717 with your request.
Identity Verification
We will verify your identity to ensure the security of your data before processing any request.
Timely Response
We respond to all data rights requests within 30 calendar days, consistent with HIPAA and state privacy law timelines.
We collect only the information necessary to provide accurate care matching. We never collect data for the purpose of selling it to third parties, and we regularly review our data collection practices to ensure they remain proportionate to our service needs.
Before collecting any sensitive information, we clearly explain what we need, why we need it, and how it will be used. Users provide informed consent before their data is shared with care communities, and they can withdraw that consent at any time.
Our platform runs on enterprise-grade cloud infrastructure that meets SOC 2 Type II standards. All data is encrypted both in transit (TLS 1.3) and at rest (AES-256), with encryption keys managed through a dedicated key management service.
Following the HIPAA minimum necessary standard, team members only have access to the specific data they need to perform their job functions. Access is reviewed quarterly and revoked immediately upon role changes or departure.
We maintain comprehensive audit logs of all data access and system activity. Automated monitoring detects and alerts on unusual access patterns, and we conduct regular security assessments and penetration testing.
All third-party service providers who may access user data are required to sign data protection agreements that hold them to the same standards we maintain. We conduct due diligence reviews of vendor security practices before engagement.
If you have any questions about our privacy practices, want to exercise your data rights, or need to report a security concern, our team is here to help.
BedMatch · bedmatch.health
We use small pieces of data stored on your device to keep this site secure and, with your permission, to personalise your experience and help us improve it for every family and provider who uses BedMatch.
You can change your preference at any time in our Privacy Policy.