Health Information, HIPAA, and Security
Effective September 16, 2026 · Last updated September 16, 2026
GRACE hears about residents’ lives, and sometimes about their health. This page explains how that information is handled, who sees it, how long it is kept, and what we will sign.
Where we are today. GRACE is pre-launch. No community is live, and no resident information is being processed by us today. What follows is therefore not a description of a running system — it is the set of commitments that bind us from the first resident onward, and the terms we will put in writing before one is enrolled. Where something is not yet in place, this page says so rather than implying otherwise. Ask us for the documentation and we will send you what exists.
1. What health-related information GRACE handles
GRACE hears about residents’ lives, and sometimes about their health. During a scheduled check-in a resident may mention pain, a fall, dizziness, sleep, appetite, or low mood. GRACE uses those mentions to produce a wellbeing signal, or, where it may need a person now, an escalation alert to on-duty staff.
GRACE does not access medical records and does not write to them. It has no connection to an electronic health record system.
2. HIPAA and business associate agreements
A care community is a HIPAA covered entity only if it transmits health information electronically in connection with a standard transaction, such as billing an insurer. Skilled nursing facilities commonly are; many assisted living and independent living communities are not.
- Where a Community is a covered entity, we act as its business associate and sign a business associate agreement before we process any resident information.
- We maintain administrative, physical, and technical safeguards under the HIPAA Security Rule, and will produce our documentation of them for your compliance team on request.
- Our service providers that may handle protected health information sign business associate agreements with us.
- Where a Community is not a covered entity, we apply the same safeguards by contract, so that a resident’s protection does not depend on how the Community happens to bill.
We do not describe GRACE as “HIPAA compliant.” HIPAA compliance is not a certification a vendor can award itself. We will tell you precisely what we do, sign an agreement that binds us to it, and give your compliance team the documentation to check it.
3. California Confidentiality of Medical Information Act
California’s CMIA (Civil Code section 56 and following) reaches beyond HIPAA. Section 56.06 treats a business that offers software designed to maintain medical information as a provider of health care for the Act’s purposes. We treat health-related information from GRACE calls as confidential medical information under the CMIA, disclose it only as the Act and our Community contracts allow, and never use it for marketing.
4. Who sees what
| Who | Sees | Does not see |
|---|---|---|
| On-duty staff | Escalation alerts with the detail needed to act, timestamps, and the audit log | A browsable record of the resident’s conversations |
| Care leadership | Wellbeing trends and check-in completion across the community | A browsable record of the resident’s conversations |
| Family members | That the check-in happened, general spirits, and messages the resident chooses to pass on | Health or medical detail, conversation content, and anything the resident declined to share — including the fact that she declined |
| kAIndness LLC personnel | Access strictly for support and safety, role-limited and logged | Routine access to call content |
5. Call recording and consent
GRACE calls are recorded. California requires the consent of all parties to record a confidential communication, so no resident is enrolled until the resident, or a legally authorized representative acting for the resident, has consented in writing to AI voice calls and to their recording and processing. GRACE states that it is an AI at the start of every call, and a resident can stop the calls at any time, with no effect on care.
For Communities licensed as health facilities, clinics, or physician practices, California Health and Safety Code section 1339.75 requires certain AI-generated patient communications about clinical information to carry a spoken disclaimer at the start and end and instructions for reaching a human. GRACE offers a call mode that adds that language for Communities subject to it.
6. Security controls
| Control | What we commit to |
|---|---|
| Encryption in transit | TLS 1.2 or higher |
| Encryption at rest | Applied to call audio, transcripts, and signals |
| Hosting region | United States |
| Speech and language processing | Runs on infrastructure we control. Resident call content is not sent to a third-party consumer AI service. |
| Access control | Role-based, with multi-factor authentication on staff accounts |
| Audit logging | Access to resident information is logged |
| AI model training on resident data | Never on identifiable resident conversations. De-identified information only, and only where the Community’s contract permits it. |
| Independent assessment | None yet. GRACE is pre-launch; we will commission one before general availability and will say so here with its date. |
| Breach notification | We notify the affected Community and support the notifications HIPAA and California law require of it |
7. Retention and deletion
Call audio and transcripts are retained for the period set in the Community’s contract, and in no case longer than 90 days, after which they are deleted automatically. Safeguarding records are the one exception, at five years. Wellbeing signals, check-in records, escalation alerts, and audit logs are kept for the term of the contract as part of the Community’s care record. A Community or a resident can ask for earlier deletion. Full detail is in our Privacy Policy.
Safeguarding records are kept longer. Where a resident discloses possible abuse, neglect, or financial exploitation, the call audio, the transcript, and the record of that escalation are copied to a separate safeguarding store and kept for five years rather than the period above, then deleted automatically. Five years is deliberate: California allows a claim for financial elder abuse to be brought within four years of discovery, and such matters are often discovered long after the conversation that revealed them. Access to that store is restricted to the Community’s designated contact and to the personnel who support it. Nothing else about the call is treated differently.
8. AI limits and escalation
GRACE’s impressions of mood are drawn from what a resident says during a call. They are impressions, not measurements, and they can be wrong. Staff should treat them as a prompt to look in on someone, never as an assessment.
GRACE never diagnoses, gives medical advice, recommends a medication, or makes any decision about a resident’s care, services, or placement.
Where a resident describes a medical emergency or expresses thoughts of self-harm, GRACE responds supportively, alerts on-duty Community staff immediately, and logs the event.
Disclosures of possible abuse, neglect, or financial exploitation follow a separate route. GRACE acknowledges what the resident said and does not question her further, because questioning a person about possible abuse can compromise a later investigation and can put her at risk. The disclosure goes immediately to the administrator or abuse-response contact the Community has designated, not to whoever is on the floor, since the person described may be on duty. It is never shown on the shared board and never shown to a family member. Community staff remain responsible for the response and for any mandated reporting under Welfare and Institutions Code section 15630.
9. Requesting our documentation
A Community evaluating GRACE can request our business associate agreement, our responses to a security questionnaire, and our current service-provider list by writing to info@gracefulcheckins.com.