What we actually do to protect your family’s information, and what we do not claim.
That sentence is deliberate, and we would rather lead with it than bury it. HelloRemind is not a healthcare provider, so HIPAA does not apply to us directly. But we handle medication schedules, recipient names, and recorded voices, and that is information that deserves the same care whether or not a regulation compels it. So we build to the HIPAA Security Rule’s technical safeguards because it is the right way to handle this data.
What we will not do is call ourselves “HIPAA compliant.” No third party has assessed us against the standard, and the phrase claims something we have not earned. The list below is what we have, stated specifically enough that you can hold us to it.
Every connection uses TLS, and our servers refuse to send your information anywhere that will not accept an encrypted connection. Our domain is on the browser preload list that makes an unencrypted request impossible in the first place.
Every phone number we hold — your loved one’s, your escalation contacts’, your own — is encrypted in our database, and searchable only through a separate one-way index. Someone reading the raw database does not read phone numbers.
Recorded and generated reminder audio, the data exports you request, and our daily database backups are all held in object storage that encrypts every object with AES-256.
When a member of our staff views data belonging to your account, that access is written to an audit trail with the account, the person, and the time. The trail is retained for seven years.
Support staff work against a masked view: they can resolve your ticket without reading full phone numbers or recipient details. Unmasked access is a separate, higher tier that is itself logged.
Separation between accounts is enforced in the data layer rather than page by page, and an automated test asserts on every build that no query can reach across accounts. A missing check fails the build instead of leaking.
A job runs daily looking for unusual access patterns — volume spikes, access outside normal hours, repeated failures — and raises them for review.
Available on every account. Required for administrator access, and re-checked before sensitive changes such as billing or deleting an organization.
Every service in this category says it is secure. Fewer say where the edges are. Here are ours.
If you are a covered entity — a provider, health plan, or clearinghouse — and you need a Business Associate Agreement in place before you can use a service like ours, tell us before you sign up rather than after. We have mapped what becoming a Business Associate requires of us, including encrypting the remaining fields named above, moving the database onto encrypted storage, and putting agreements in place with each of our providers. It is a real project with a real sequence, and we would rather scope it honestly with you than promise it is already done.
Care agencies and family offices that are not covered entities can use HelloRemind today on our standard terms.
Found something? Email hi[at]helloremind[dot]me with the details and we will come back to you. Please give us a chance to fix it before publishing.
Support is not monitored for emergencies. If someone needs urgent help, call 911.
For what we collect, who receives it, and how to delete it, see our Privacy Policy. For how consent works on text reminders, see our Messaging Policy.