Ohio’s Turn-Key DODD Compliance Platform.Not affiliated with the Ohio Department of Developmental Disabilities
Security and HIPAA

Security and HIPAA

How we protect the limited protected client information stored in DODD Agency Pro, and the responsibilities we share with the agencies we serve.

Our Safeguards

DODD Agency Pro applies administrative, physical, and technical safeguards to protect the limited protected client information it stores on behalf of provider agencies. Client Compliance Tracking encrypts client names at rest with AES-256-GCM. Other enabled client-related features may store operational fields and rely on tenant isolation and access controls unless specifically stated. Access is restricted to authorized users through per-organization isolation and least-privilege role permissions, all traffic is encrypted in transit with TLS, and Client Compliance Tracking actions are written to an application audit log with chained hashes. Field-level encryption at rest is applied to Client Compliance Tracking records; other operational records are protected by those access controls rather than by field-level encryption. The platform is designed to support HIPAA-compliant operations; it is not automatically, certifiably, or guaranteed HIPAA compliant.

At a Glance

Encryption

All traffic is encrypted in transit with TLS. In Client Compliance Tracking, client names are additionally encrypted at rest with AES-256-GCM.

Access control

Records are isolated per organization and reachable only through least-privilege role permissions granted to authorized users.

Audit trail

Client Compliance Tracking writes application audit events with chained hashes to help reviewers detect changes to logged history.

Data minimization

Client-related features define bounded fields and are not intended to replace an agency's clinical record system.

A Shared Responsibility

HIPAA compliance is a shared responsibility. The platform supplies technical safeguards and records; each agency owns its own risk decisions, workforce policies, training, physical safeguards at its locations, and day-to-day operational compliance. Where an executed Business Associate Agreement applies, it governs DODD Agency Pro's handling of protected information. Implementing the platform's controls does not, by itself, establish HIPAA compliance for your agency.

Business Associate Agreements are available when applicable and must be executed before protected client information is entered.

What our Business Associate Agreement covers

Found a vulnerability, or think client information may have been exposed? Tell us. We publish how a report is acknowledged, contained, investigated and remediated.

Report a security concern