Your session will end and you'll be returned to the sign-in screen. Any unsaved work will be lost.
—
Signed in
Platform Operations
Switch to Production?
Actions taken in production affect live tenants. Confirm you intend to operate against the production environment.
Modal
My Profile
New message
Search for a recipient. Clinical providers and nurses are reachable only via authorized support threads.
HIPAA Compliant
Secure · Reliable · Always
LoopWell is built to the U.S. HIPAA Security Rule (45 CFR §164.308–.312) and the Privacy Rule. Every safeguard below is implemented in the platform — not promised, enforced.
Administrative safeguards
Role-based access control. Every user is scoped to an organization and a least-privilege role; no cross-tenant reads are possible.
Workforce training & BAA. A signed Business Associate Agreement is required before any PHI flows.
Breach response. Documented incident-response runbook; affected covered entities are notified within 60 days as required.
Technical safeguards
Encryption in transit. TLS 1.2+ on every API and asset request; HSTS enforced.
Encryption at rest. AES-256 on the database and on every uploaded artifact.
Audit trail. Every PHI access, edit, export, and follow-up action is timestamped, attributed, and immutable.
Automatic logoff. Idle sessions terminate to prevent unattended exposure.
Physical & operational safeguards
SOC 2-aligned hosting. Production runs on infrastructure with physical access controls, redundancy, and continuous monitoring.
Backups. Encrypted point-in-time backups with tested restore procedures.
Data minimization. Only the PHI strictly required for the follow-up workflow is stored; nothing is sold, shared, or used to train models.
Questions, BAA requests, or to report a security concern: security@trinityops.health.
LoopWell acts as a Business Associate under HIPAA when handling Protected Health Information on behalf of a Covered Entity.