RK1Care

Security and data

This page describes how RK1Care, Inc. designs CareLogs and related products to protect personal information. It is an overview of our current technical posture. It is not a HIPAA certification, a security audit report, a Business Associate Agreement, legal advice, or a warranty.

What we may retain

The public website (www.rk1care.com) is meant for ordinary browsing. Do not send health information here.

CareLogs, when a customer uses it, may retain:

  • PII — names, emails, rooms, and account identifiers for staff, families, and people in the home.
  • Health and care records (ePHI / CIS) — medications, eMAR activity, care tasks, incidents, and related notes entered by the customer.
  • Operational logs — readable summaries of care and chart changes, kept in quarterly archives for up to two years.
  • Technical audit records — who accessed which system route, stored as identifiers (not names or note text), with a longer retention setting aligned to common HIPAA documentation practice (up to six years).
  • Photos and labels — resident or medication photos the customer uploads, and public images fetched from NIH DailyMed when used.

Future RK1Care products (for example on a phone or watch) may retain similar classes of data. We will describe those products when they ship. Until then, do not assume a capability exists.

HIPAA

RK1Care is not a HIPAA “certification” body, and shipping CareLogs does not make a home HIPAA compliant. Homes and other customers remain responsible for their own legal duties, including whether they are a covered entity or business associate, workforce training, incident response, and agreements with their residents and families.

We do not intend CareLogs to hold real protected health information in production until RK1Care and the customer have a signed Business Associate Agreement (and RK1Care has a signed BAA with Microsoft Azure and any other subprocessors we use). Until those agreements are in place, use only non-production or de-identified test data.

How we protect information

  • Encryption in transit (TLS) and encryption at rest in our hosted database environment.
  • Production sign-in intended through Microsoft Entra with multi-factor authentication.
  • Role-based access so families see a limited daily picture, not the full chart.
  • Application audit logging of access (identifiers, not clinical note bodies).
  • We do not sell personal information.

No internet service is perfectly secure. Customers must also protect devices, passwords, physical access, and who they invite into the product.

Your and our roles

The customer controls what is entered into CareLogs and is the source of records about people in the home. RK1Care provides software and hosting. We are not the licensed operator of any home, not a medical provider, and not responsible for clinical decisions, medication accuracy, or whether a record is complete. NIH DailyMed and similar public sources are provided for convenience only and are not medical advice.

Back to RK1Care·Privacy·Terms