Security and Privacy

What we actually do to protect your family’s information, and what we do not claim.

Built to HIPAA standards. Not certified, not audited, not a Business Associate.

That sentence is deliberate, and we would rather lead with it than bury it. HelloRemind is not a healthcare provider, so HIPAA does not apply to us directly. But we handle medication schedules, recipient names, and recorded voices, and that is information that deserves the same care whether or not a regulation compels it. So we build to the HIPAA Security Rule’s technical safeguards because it is the right way to handle this data.

What we will not do is call ourselves “HIPAA compliant.” No third party has assessed us against the standard, and the phrase claims something we have not earned. The list below is what we have, stated specifically enough that you can hold us to it.

What we do

Encrypted in transit, everywhere

Every connection uses TLS, and our servers refuse to send your information anywhere that will not accept an encrypted connection. Our domain is on the browser preload list that makes an unencrypted request impossible in the first place.

Phone numbers encrypted at rest

Every phone number we hold — your loved one’s, your escalation contacts’, your own — is encrypted in our database, and searchable only through a separate one-way index. Someone reading the raw database does not read phone numbers.

Audio, exports, and backups encrypted at rest

Recorded and generated reminder audio, the data exports you request, and our daily database backups are all held in object storage that encrypts every object with AES-256.

Every access to your information is logged

When a member of our staff views data belonging to your account, that access is written to an audit trail with the account, the person, and the time. The trail is retained for seven years.

Staff see the minimum necessary

Support staff work against a masked view: they can resolve your ticket without reading full phone numbers or recipient details. Unmasked access is a separate, higher tier that is itself logged.

Accounts cannot see each other

Separation between accounts is enforced in the data layer rather than page by page, and an automated test asserts on every build that no query can reach across accounts. A missing check fails the build instead of leaking.

Automated breach detection

A job runs daily looking for unusual access patterns — volume spikes, access outside normal hours, repeated failures — and raises them for review.

Two-factor authentication

Available on every account. Required for administrator access, and re-checked before sensitive changes such as billing or deleting an organization.

What we do not claim

Every service in this category says it is secure. Fewer say where the edges are. Here are ours.

We are not HIPAA certified
There is no such thing as HIPAA certification from the government, and no third party has audited us against the standard. Any company telling you it is "HIPAA certified" is describing a private audit at best.
We are not a Business Associate by default
HelloRemind is a consumer service. We are not a healthcare provider, so HIPAA does not apply to us directly, and we do not sign Business Associate Agreements as a matter of course. If you are a covered entity that needs one, talk to us before you sign up — see below.
Not everything is encrypted at rest
Reminder titles and messages, and recipient names, are stored in readable form in our database so the service can schedule, search, and speak them. Encrypting them is designed and costed, and is the first thing we build for a healthcare customer. We would rather tell you than let you assume.
We have not had an external penetration test
The controls above are real and testable, but they have been reviewed by us, not by an outside firm.

If you are a healthcare organization

If you are a covered entity — a provider, health plan, or clearinghouse — and you need a Business Associate Agreement in place before you can use a service like ours, tell us before you sign up rather than after. We have mapped what becoming a Business Associate requires of us, including encrypting the remaining fields named above, moving the database onto encrypted storage, and putting agreements in place with each of our providers. It is a real project with a real sequence, and we would rather scope it honestly with you than promise it is already done.

Care agencies and family offices that are not covered entities can use HelloRemind today on our standard terms.

Reporting a vulnerability

Found something? Email hi[at]helloremind[dot]me with the details and we will come back to you. Please give us a chance to fix it before publishing.

Support is not monitored for emergencies. If someone needs urgent help, call 911.

For what we collect, who receives it, and how to delete it, see our Privacy Policy. For how consent works on text reminders, see our Messaging Policy.