HIPAA and health data
How NurturaCare handles protected health information, when it acts as a business associate, and what that means for you and for regulated organisations.
Last updated June 1, 2026
When HIPAA applies
HIPAA applies to covered entities — most healthcare providers and health plans — and to their business associates. A direct-to-consumer wellness app is not automatically covered.
When you use NurturaCare through a clinic, hospital or health plan, we act as that organisation’s business associate for the protected health information we handle on their behalf, under a signed business associate agreement.
When you sign up directly as a consumer, HIPAA generally does not apply to your account — but the FTC Health Breach Notification Rule may, and our security and privacy commitments apply to you identically.
What that means in practice
We built the architecture so a HIPAA-regulated deployment is a configuration, not a rewrite.
- Encryption in transit and at rest, with field-level encryption for free-text health data.
- Role-based access control, least privilege, and mandatory MFA for staff accounts.
- An append-only audit trail of every access to member data, protected by a database trigger.
- Row-level security enforcing organisation isolation at the database, not only in application code.
- Documented incident response, breach investigation and notification workflows.
- Business associate agreements with every vendor that may handle protected health information.
Breach notification
We maintain incident classification, investigation and notification procedures covering both HIPAA breach notification and the FTC Health Breach Notification Rule, along with evidence retention and vendor incident obligations.
This is not legal advice
This page describes our engineering and operational posture. Whether HIPAA applies to a specific deployment is a legal determination made with counsel.