๐Ÿฅ

HIPAA

Administrative, physical & technical safeguards for PHI. BAA available for covered entities.

โœ“ Compliant
๐Ÿ‡ช๐Ÿ‡บ

GDPR

Full compliance for EU/EEA users. DPA and SCCs available for data controller customers.

โœ“ Compliant
๐ŸŒด

CCPA / CPRA

California consumer rights: know, delete, correct, limit. No sale of personal information.

โœ“ Compliant
๐Ÿ›๏ธ

BIPA (Illinois)

Written policy, consent, non-sale, and destruction schedule for biometric identifiers (voice prints).

โœ“ Compliant
๐Ÿ”

SOC 2 Type II

Security, availability, and confidentiality controls. Report available under NDA.

In Progress
โ™ฟ

WCAG 2.1 AA

Accessibility standards for senior users. Ongoing accessibility audits and remediation.

Ongoing

HIPAA Compliance

KinBridge supports HIPAA-covered entities (hospices, skilled nursing facilities, employer health plans) with a complete suite of technical, administrative, and physical safeguards.

Technical Safeguards

Administrative Safeguards

Physical Safeguards

Need a Business Associate Agreement (BAA)?

Required for all HIPAA-covered entities using KinBridge to store or process PHI. We execute BAAs within 2 business days.

Request BAA โ†’
DocumentPurposeAvailability
Business Associate Agreement (BAA) HIPAA compliance for covered entities processing PHI On request โ€” email enterprise
Data Processing Agreement (DPA) GDPR compliance for EU/EEA data controllers; includes Standard Contractual Clauses On request โ€” email enterprise
Master Service Agreement (MSA) Commercial terms, SLA, and enterprise-specific obligations Included with Enterprise plan contracts
Sub-Processor List Complete list of third-party processors handling customer data Published at Privacy Policy โ€” Sub-processors
Penetration Test Summary Annual third-party security assessment results Available under NDA โ€” request from security
SOC 2 Type II Report Independent audit of security controls In progress โ€” available under NDA upon completion

User & Patient Data Rights

KinBridge supports the following data subject rights required by HIPAA, GDPR, and CCPA:

RightHow to ExerciseResponse Time
Access / Right to KnowSettings โ†’ Privacy, or email30 days (GDPR) / 45 days (CCPA)
Correction / RectificationSettings โ†’ Profile, or email30 days
Deletion / ErasureSettings โ†’ Account โ†’ Delete, or email30 days (data), 90 days (backups)
Data PortabilityEmail privacy30 days
Restrict ProcessingEmail privacy72 hours for acknowledgment
Biometric Destruction (BIPA)Email privacy72 hours
HIPAA Right of AccessEnterprise admin dashboard or email30 days

Incident Response & Breach Notification

KinBridge maintains a documented incident response plan. In the event of a security incident involving personal data:

To report a security concern: security@kinbridge.app. See our Security page for responsible disclosure.

AI & Algorithmic Transparency

KinBridge is an AI-powered platform. Our AI compliance commitments:

Contact Compliance Team

Enterprise compliance: enterprise@kinbridge.app
Privacy / DPO: dpo@kinbridge.app
Security incidents: security@kinbridge.app
BAA / DPA requests: enterprise@kinbridge.app