● New: Minnesota payroll is now in early access inside Certify245D. See payroll →
Security & HIPAA

Client records deserve more than a password

Certify245D holds protected health information for people who depend on your agency. Here's specifically how it's protected.

☁️

Google Cloud, under a BAA

The application and database run on Google Cloud, covered by a signed Business Associate Agreement. Data is encrypted in transit and at rest.

🧱

Isolation in the database

Each agency's records are separated by row-level security enforced in the database itself — not only by what the screens show.

👥

Role-based access

Owners, managers, coordinators, staff and auditors each see only what their role needs.

📁

Your documents, your Drive

Agency documents are filed to the agency's own Google Drive folder, not locked in a vendor's storage.

⏳

Access that expires

Auditors get read-only access to only the files you select, with an end date. No shared logins.

📜

Audit trail

Access and changes are logged, including every file an auditor views.

🔗

Signing links that expire

Case managers and signers use single-use links. Re-sending revokes the old link automatically.

🔏

Tamper-evident signatures

Signed documents carry a certificate page with a SHA-256 fingerprint of exactly what the signer was shown. Originals are never overwritten.

🧑‍⚕️

People review AI drafts

AI drafts of plans are starting points only. Qualified staff review and finalize every one before it's used.

Minimum necessary

Built around how 245D records actually flow

  • Release of information, renewed yearly. The standing release covers routine care coordination; anything beyond it is authorized at the time and recorded in a disclosure log.
  • Staff uploads are reviewed. Anything an employee uploads is checked before it becomes part of the official record.
  • History is kept, not overwritten. Ended assignments and case-manager-signed copies are stored alongside the originals.

Certify245D provides safeguards; HIPAA compliance also depends on your agency's own policies, training and practices. Ask us for a copy of our Business Associate Agreement.

FAQ

Security questions

Where is Certify245D hosted?

On Google Cloud, under a signed Business Associate Agreement. Agency documents are stored in the agency's own Google Drive folder, not in a vendor's storage.

Can one agency see another agency's data?

No. Tenant isolation is enforced by row-level security in the database itself, not only by the application screens.

More answers on the FAQ page →

Ready when you are

Questions from your privacy officer?

We're glad to walk through the details on a call.