Security

Your residents’ health information is always secure and private.

HIPAA PHIPA PIPEDA CSA

How We Protect Residents' Health Information

At Evoke Health, we understand the critical importance of safeguarding residents' health information. Our platform employs industry-leading privacy and security measures to protect all Personal and Personal Health Information (PHI), ensuring the same encryption standards used by your EHR.

  1. Comprehensive Compliance
  2. We comply with all applicable privacy laws and regulations to ensure the highest standards of protection, including:

    • HIPAA (Health Insurance Portability and Accountability Act)
    • PIPEDA (Personal Information Protection and Electronic Documents Act)
    • PHIPA (Personal Health Information Protection Act)
    • PIPA (Personal Information Protection Act)
  3. Certifications and Independent Verification
  4. Our security posture is validated by independent third parties, not just internal policy:

    • Cloud Security Alliance (CSA) STAR Level 1 Certified: We maintain CSA STAR certification, demonstrating security in our cloud security controls.
    • Annual OWASP ASVS Level 2 Penetration Testing: Every year, an independent third party conducts penetration testing aligned to the OWASP Application Security Verification Standard (ASVS) Level 2.
  5. Encryption Standards You Can Trust
  6. All resident health data is encrypted at rest using AES-256 and in transit using TLS 1.2+ — the same advanced encryption technology trusted by EHRs like PointClickCare.

  7. Robust Access Controls, Monitoring, and Threat Detection
    • Access logs are meticulously maintained and reviewed to ensure that only authorized parties access the data.
    • Employees with system access adhere to strict confidentiality agreements, providing an added layer of security.
    • Real-time security monitoring, threat detection, and incident response ensure continuous protection against potential cybersecurity risks.

Ongoing Security Enhancements

We continuously evaluate and adapt our privacy and security policies to meet evolving standards, ensuring resident health information remains secure at all times.

Your Role in Protecting Access

While we implement rigorous security measures, it’s important to protect your access credentials. Please keep your Evoke Health account password secure to prevent unauthorized access.

Why Trust Evoke Health with Resident Information?

Evoke Health combines certified cloud security, independently verified penetration testing, and industry standard security practices to give long-term care homes complete confidence in how resident information is handled. Our dedication to compliance, transparency, and continuous improvement makes us the trusted choice for family communication and engagement.