Security

How we protect your data

Your family's health information is sensitive. We protect it with the same security standards used by hospitals and health systems.

Encryption everywhere

All data is encrypted in transit using TLS and at rest using AES-256 encryption. Your family health information is protected whether it's moving between your device and our servers or stored in our database.

Access controls

We implement role-based access controls to ensure that only authorized personnel can access sensitive systems. Access is logged, audited, and reviewed regularly.

Vendor oversight

Third-party services that interact with your data are held to the same security standards we hold ourselves to. We evaluate vendors for security practices before integration and monitor them on an ongoing basis.

Breach response

Our breach response procedures align with the FTC Health Breach Notification Rule. In the unlikely event of a data breach, we will notify affected users promptly and transparently.

Data minimization

We collect only the information necessary to provide the service. We retain identifiable data only as long as needed, and you can request deletion of your data at any time.

Kinvera aligns with the following regulatory frameworks to protect users across all states:

FTC Health Breach Notification Rule
CCPA / CPRA (California)
My Health My Data Act (Washington)
MODPA (Maryland)
Colorado Privacy Act
VCDPA (Virginia)
CTDPA (Connecticut)
TDPSA (Texas)
UCPA (Utah)

Have questions about our security practices? We're happy to discuss them.

Kinvera Health

Email: [email protected]