Security and HIPAA
How we protect the limited protected client information stored in DODD Agency Pro, and the responsibilities we share with the agencies we serve.
DODD Agency Pro applies administrative, physical, and technical safeguards to protect the limited protected client information it stores on behalf of provider agencies. Client Compliance Tracking encrypts client names at rest with AES-256-GCM. Other enabled client-related features may store operational fields and rely on tenant isolation and access controls unless specifically stated. Access is restricted to authorized users through per-organization isolation and least-privilege role permissions, all traffic is encrypted in transit with TLS, and Client Compliance Tracking actions are written to an application audit log with chained hashes. Field-level encryption at rest is applied to Client Compliance Tracking records; other operational records are protected by those access controls rather than by field-level encryption. The platform is designed to support HIPAA-compliant operations; it is not automatically, certifiably, or guaranteed HIPAA compliant.
HIPAA compliance is a shared responsibility. The platform supplies technical safeguards and records; each agency owns its own risk decisions, workforce policies, training, physical safeguards at its locations, and day-to-day operational compliance. Where an executed Business Associate Agreement applies, it governs DODD Agency Pro's handling of protected information. Implementing the platform's controls does not, by itself, establish HIPAA compliance for your agency.
Business Associate Agreements are available when applicable and must be executed before protected client information is entered.
What our Business Associate Agreement coversFound a vulnerability, or think client information may have been exposed? Tell us. We publish how a report is acknowledged, contained, investigated and remediated.
Report a security concern