Privacy & Security

HIPAA-Aligned
By Design

While BedMatch is not currently required to be a HIPAA-covered entity, we have proactively designed HIPAA-grade privacy and security safeguards into every layer of our platform — because your family's sensitive information deserves the highest standard of protection.

End-to-End Encryption
Access Controls
Audit Logging
Our Commitment

Why We Build to HIPAA Standards

BedMatch handles sensitive information about seniors, their health needs, care preferences, and family circumstances. Even though our platform may not fall under the strict regulatory definition of a HIPAA-covered entity or business associate, we believe that the nature of the data we handle demands the same level of care and protection that HIPAA requires.

Proactive, Not Reactive

Rather than waiting for regulatory requirements to catch up, we've embedded HIPAA-grade safeguards from day one. Our security architecture was designed with healthcare data standards in mind from the very first line of code.

Trust Is Our Foundation

Families trust us with deeply personal information about their loved ones. Care providers share operational data through our platform. That trust is sacred, and we protect it with the same rigor that HIPAA demands of hospitals and insurers.

Future-Ready Compliance

As BedMatch grows and our role in the care placement ecosystem expands, we are positioned to achieve full HIPAA compliance seamlessly — because the infrastructure, policies, and practices are already in place.

Our Safeguards

Three Pillars of Protection

Following the HIPAA Security Rule framework, BedMatch implements comprehensive safeguards across all three categories: administrative, physical, and technical. These work together to create a layered defense for your data.

Administrative

  • Designated privacy and security officers oversee all data handling practices
  • Regular workforce training on privacy policies and secure data handling
  • Documented policies and procedures for data access, use, and disclosure
  • Incident response plan for identifying, reporting, and mitigating data breaches
  • Business associate agreements with all third-party vendors who access user data

Physical

  • Data hosted on SOC 2 Type II certified cloud infrastructure with enterprise-grade physical security
  • Redundant data storage across geographically separated data centers
  • Strict access controls to production environments limited to authorized personnel
  • Automated backups with encrypted storage to prevent data loss
  • Network segmentation isolating sensitive data from public-facing services

Technical

  • AES-256 encryption for data at rest and TLS 1.3 for all data in transit
  • Role-based access controls (RBAC) ensuring minimum necessary access to data
  • Multi-factor authentication (MFA) available for all user accounts
  • Comprehensive audit logging tracking all access to and modifications of sensitive data
  • Automated session timeouts and secure token management to prevent unauthorized access
Data Protection

What Information We Protect

BedMatch collects and processes several categories of sensitive information to provide accurate care matching. Every piece of data is treated with the same level of protection regardless of its classification.

Personal Identifiers

  • Names and contact information
  • Family relationships
  • Emergency contacts
  • Account credentials

Health & Care Needs

  • Medical conditions and diagnoses
  • Medication requirements
  • Mobility and cognitive status
  • Care level assessments

Placement Preferences

  • Location preferences
  • Budget and financial info
  • Lifestyle requirements
  • Religious or cultural needs

Platform Activity

  • Search and match history
  • Community interactions
  • Messages and inquiries
  • Document uploads
Your Rights

You Are in Control of Your Data

BedMatch is committed to transparency and user empowerment. Consistent with the principles outlined in the HIPAA Privacy Rule and applicable state privacy laws, we provide you with meaningful control over your personal information.

Right to Access

Request a copy of all personal information we hold about you or your loved one at any time.

Right to Correction

Request corrections to any inaccurate or incomplete information in your account.

Right to Deletion

Request that we delete your personal data, subject to legal retention requirements.

Right to Restrict Processing

Limit how we use your data for specific purposes, including marketing communications.

Right to Data Portability

Receive your data in a structured, commonly used format for transfer to another service.

Right to Be Informed

Receive clear notice about what data we collect, how we use it, and who we share it with.

How to Exercise Your Rights

1

Submit a Request

Email [email protected] or call (888) 450-8717 with your request.

2

Identity Verification

We will verify your identity to ensure the security of your data before processing any request.

3

Timely Response

We respond to all data rights requests within 30 calendar days, consistent with HIPAA and state privacy law timelines.

In Practice

How We Put Privacy Into Action

Data Minimization

We collect only the information necessary to provide accurate care matching. We never collect data for the purpose of selling it to third parties, and we regularly review our data collection practices to ensure they remain proportionate to our service needs.

Transparency & Consent

Before collecting any sensitive information, we clearly explain what we need, why we need it, and how it will be used. Users provide informed consent before their data is shared with care communities, and they can withdraw that consent at any time.

Secure Infrastructure

Our platform runs on enterprise-grade cloud infrastructure that meets SOC 2 Type II standards. All data is encrypted both in transit (TLS 1.3) and at rest (AES-256), with encryption keys managed through a dedicated key management service.

Minimum Necessary Access

Following the HIPAA minimum necessary standard, team members only have access to the specific data they need to perform their job functions. Access is reviewed quarterly and revoked immediately upon role changes or departure.

Continuous Monitoring

We maintain comprehensive audit logs of all data access and system activity. Automated monitoring detects and alerts on unusual access patterns, and we conduct regular security assessments and penetration testing.

Vendor Management

All third-party service providers who may access user data are required to sign data protection agreements that hold them to the same standards we maintain. We conduct due diligence reviews of vendor security practices before engagement.

FAQ

Frequently Asked Questions

Questions or Concerns?

If you have any questions about our privacy practices, want to exercise your data rights, or need to report a security concern, our team is here to help.

Privacy Officer

[email protected]

For data rights requests and privacy inquiries

Call Us

(888) 450-8717

Mon–Fri, 8:00 AM – 6:00 PM CT

Report a Concern

[email protected]

For security incidents or vulnerabilities

Your Privacy, Your Choice

BedMatch · bedmatch.health

We use small pieces of data stored on your device to keep this site secure and, with your permission, to personalise your experience and help us improve it for every family and provider who uses BedMatch.

You can change your preference at any time in our Privacy Policy.