Back to home

Trust & security

A practical reference for when regulated claims and third-party certification marks belong on the site. Use it with your counsel and assessors, not instead of them.

Not legal advice

Caresoft.ai does not guarantee HIPAA, HITRUST, PCI, or any other framework outcome. This page is not a substitute for counsel, assessors, BAAs, policies, or your own risk analysis.

Before the seals go on the homepage

  1. HIPAA and PHI

    • Keep minimum-necessary access, encrypt data in transit, and use strong authentication in line with common Security Rule practice.
    • Sign Business Associate Agreements (BAAs) with any subprocessor that touches PHI.
    • Have counsel sign off before the marketing site says “HIPAA compliant” or similar.
  2. HITRUST CSF or SOC 2

    • Pick a target (for example HITRUST i1 or SOC 2) with whoever owns compliance at your organization.
    • Run a readiness review and close the gaps you care about.
    • After certification, use only the official marks and follow that program’s trademark rules.
  3. PCI DSS

    • Map where cardholder data flows and whether Caresoft.ai, your gateway, or both sit in scope.
    • File the SAQ that fits your setup, or bring in a QSA if you need one.
    • Add PCI-related logos only when your acquirer and PCI SSC rules say you may.

Badges on the marketing homepage

The home page shows program marks as supplied by each issuer. When a body updates its artwork, swap the SVG or image they publish. Remove or rewrite the small-print note under the marks when your counsel says it is no longer needed.