HIPAA Compliance13/13 active
HTTPS/TLS15-Min TimeoutDB EncryptionS3 EncryptionRBACAudit LoggingOAuthRate LimitingNo Hardcoded SecretsHealth MonitoringAuto-RecoveryDB Backups
Connection Retry

HIPAA Compliance & Privacy

WeCare is committed to protecting the privacy and security of health information. Here's how we safeguard your data.

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that sets national standards for protecting sensitive patient health information. It requires organizations that handle Protected Health Information (PHI) to implement physical, technical, and administrative safeguards.

Because WeCare handles healthcare-related delivery data, we follow HIPAA guidelines to ensure every piece of information is handled responsibly.

How We Protect Your Data

  • Encryption in transit — all connections use HTTPS/TLS
  • Encryption at rest — files stored in AWS S3 are encrypted server-side
  • Session timeouts — sessions expire after 15 minutes of inactivity
  • Role-based access control — users only see what their role permits
  • Activity logging — all data changes are tracked for accountability
  • Secure authentication — Google OAuth with JWT-based sessions

Our Technology

WeCare Driver Portal is built with industry-standard tools chosen for security and reliability:

  • Next.js — server-rendered React framework with built-in security headers
  • PostgreSQL — enterprise-grade database with row-level access controls
  • AWS S3 — encrypted cloud storage for attachments and files
  • Google OAuth — secure sign-in without storing passwords
  • HTTPS / TLS — all data encrypted in transit between your browser and our servers

Your Rights Under HIPAA

As an individual whose information may be handled by WeCare, you have the right to:

  • Access — request a copy of your data we hold
  • Amendment — ask us to correct inaccurate information
  • Restriction — request limits on how your data is used or shared
  • Accounting — obtain a record of certain disclosures of your information
  • Complaint — file a complaint with us or the U.S. Department of Health & Human Services if you believe your rights have been violated

Data We Collect

We only collect information necessary to operate the delivery management system. This includes:

  • User profiles — name, email, role, and profile photo
  • Delivery records — addresses, dates, statuses, and notes
  • Expense logs — amounts, categories, and receipt attachments
  • Activity logs — who changed what and when, for audit purposes

We do not store direct Protected Health Information (PHI) beyond what is strictly necessary for delivery coordination.

Who Has Access

Access is strictly controlled by role:

Admin

Full system access — manage users, view all deliveries and expenses, configure integrations, and access activity logs.

Case Manager

View and edit all deliveries, assign and reassign drivers, and access activity logs. Cannot manage users or integrations.

Driver

View and manage only their own deliveries and expenses. No access to other users' data.

System Resilience

Our production infrastructure includes multiple layers of protection to ensure data safety and uptime:

  • Health Monitoring — automated checks every 2 minutes with auto-restart on failure
  • Auto-Recovery — PM2 process manager automatically restarts the app on crashes or memory issues
  • Database Backups — automated daily backups to encrypted S3 storage with 30-day retention
  • Connection Retry — database queries automatically retry with backoff on transient connection failures

Last Backup

Apr 12, 2026, 8:00 PM

Last Incident

Mar 24, 2026, 1:54 PM

Recent System Events (72h)

info

Backup complete: wecare_drive_2026-04-13_0300.sql.gz (528K)

Apr 12, 2026, 8:00 PM

info

Backup complete: wecare_drive_2026-04-12_1500.sql.gz (528K)

Apr 12, 2026, 8:00 AM

info

Backup complete: wecare_drive_2026-04-12_0300.sql.gz (528K)

Apr 11, 2026, 8:00 PM

info

Backup complete: wecare_drive_2026-04-11_1500.sql.gz (528K)

Apr 11, 2026, 8:00 AM

info

Backup complete: wecare_drive_2026-04-11_0300.sql.gz (528K)

Apr 10, 2026, 8:00 PM

info

Backup complete: wecare_drive_2026-04-10_1500.sql.gz (524K)

Apr 10, 2026, 8:00 AM

Questions or Concerns?

If you have questions about our privacy practices or believe your rights have been violated, please contact our Privacy Officer:

(925) 462-5600

DriveApp V 3.0·Built Apr 1, 2026, 5:12 PM
HIPAA Compliant