Security & governance
Built for your diligence review.
Everything below is one line here and a full document in the diligence pack. Ask for it.
HIPAA / HITECH adherence
The federal rules for handling health information. We follow them.
SOC 2 Type II-aligned controls
Our security practices follow the SOC 2 Type II framework.
BAAs with all subprocessors
Signed agreements hold every vendor we use to the same privacy rules.
Tenant-scoped isolation
Each organization's data lives separately from every other's.
Encryption in transit and at rest
Data is encoded while moving and while stored.
PHI minimization
Carrie handles only the personal health information a Program needs, nothing more.
TCPA-compliant outbound, with STIR/SHAKEN
Calls follow federal calling rules, and carriers can verify they really come from your practice.
Model-agnostic AI layer
Carrie's AI layer swaps models as better or safer ones emerge, so the platform is never tied to a single AI vendor.
Consent, embedded
Patient consent sits in the practice's standard and procedural consents, the paperwork patients already sign.
How the AI is governed.
Every call runs a Program: a version-controlled clinical playbook, immutable once released. A second, independent AI checks every sentence of every call in real time for emergencies. The Human Oversight Team, licensed clinicians, verifies every flagged concern, urgent ones within 1 hour. And every conversation lands in an immutable audit log that can be replayed exactly. The full governance model is on How Carrie works.
Carrie never diagnoses, prescribes, or places orders; clinical judgment stays with the care team.
Your security team will have questions. The pack answers them.