trust

Security, cloud & integration

Built for HIPAA-regulated care, with AWS cloud infrastructure and a clear plan for deployment, clinical-system connections, and staff sign-in.

Built for HIPAA-regulated care.

Care depends on trust. genusConnect combines encryption, access controls, and operating practices designed to support the protection of sensitive information. Our documented AWS relationship includes a Business Associate Agreement (BAA).

HIPAA-compliant care requires technology, agreements, risk assessment, and day-to-day practices to work together. Before a program handles protected health information, we work through the applicable responsibilities and deployment requirements with the partner.

Read HHS guidance on HIPAA and cloud computing.

AWS infrastructure

A cloud foundation for sensitive care information.

genusConnect runs on Amazon Web Services (AWS). Our infrastructure brings together managed identity, encrypted databases and storage, and application services that support care programs.

AWS is responsible for the security of its cloud infrastructure. genusConnect and its partners remain responsible for the way the application is configured and used, including access, data handling, and operating practices.

  • Encryption and access controls help protect sensitive information in transit and at rest.
  • Database backup and recovery capabilities support continuity planning.
  • The AWS services handling protected health information must be covered by the applicable Business Associate Agreement (BAA) and service eligibility requirements.

genusAI

genusAI handles information according to its sensitivity.

genusAI uses frontier models for de-identified information. Sensitive information is handled by private internal models running on genusConnect’s own hardware and data systems.

Cloud deployment

Agree the deployment before bringing in live care data.

Start with the program, the people using it, and the information it needs. A branded preview can use sample people and sample notes while the team works through the operating requirements.

genusConnect supports managed AWS deployment, with a separate workload account available as a scoped deployment option. Environment ownership, region, permissions, integrations, and support responsibilities are agreed for the project.

  • Define who operates the environment and who administers partner access.
  • Review data retention, backups, recovery expectations, and incident contacts.
  • Validate the agreed workflows and connections before introducing live protected health information.

HL7 & FHIR

Connect clinical information around a clear care need.

HL7 develops standards for exchanging health information. FHIR, or Fast Healthcare Interoperability Resources, is one of those standards and supports exchanging defined healthcare data through interfaces such as APIs.

HL7 v2 and FHIR connections are scoped with your IT team and system vendors. The available interfaces, information to be exchanged, permissions, and care workflow determine the approach and implementation effort.

  • Agree the sending and receiving systems, data fields, and patient-matching approach.
  • Define consent and access rules, error handling, and who supports the connection.
  • Test the agreed interface before relying on it in a live program. Connection availability is confirmed for each project.

Single sign-on

Plan staff sign-in with your identity team.

Single sign-on (SSO) can let staff use their organization’s identity to access a connected service. genusConnect uses Amazon Cognito for current authentication; partner SSO is scoped implementation work.

Together, we evaluate SAML or OpenID Connect (OIDC), the organization’s identity provider, and the permissions staff need. A successful sign-in still needs the right application role and organization access.

  • Agree identity-provider configuration, role mapping, and multifactor authentication requirements.
  • Plan account creation, staff changes, access removal, and session behavior.
  • Confirm the connection and test the staff journey before enabling it for the program.

Policies and safeguards

TERMS OF USE

See our Terms of Use for platform terms.

PRIVACY POLICY

See our Privacy Policy for data practices.

Encryption & Secure Hosting

All traffic is protected with SSL/TLS, and sensitive data, including PHI, is encrypted at rest inside HIPAA-aligned infrastructure.

Access Controls & Monitoring

Role-based permissions ensure only authorized clinicians, staff, or designated partners can view PHI. System activity is logged and reviewed for security and compliance.

Incident Response

Formal response playbooks guide containment, investigation, and notification. If PHI or other sensitive data is affected, users and partners are notified without unreasonable delay, consistent with legal requirements.

Employee Training & Contingency Planning

Every team member receives privacy and HIPAA training at hire and on a recurring basis, and we maintain backup plus disaster recovery strategies to protect availability.

Responsible AI and Data Governance

HIPAA COMPLIANCE POLICY

Your privacy rights

CCPA, CPRA, and GDPR protections

We honor regional privacy laws by giving every user choice, visibility, and control. These are the core rights you can exercise at any time by emailing support@genusconnect.org.

  • Right to know what personal information we collect, how we use it, and with whom we share it.
  • Right to access, correct, or delete certain personal information, subject to legal and contractual obligations.
  • Right to opt out of any sale or certain sharing of personal information where such concepts apply; we do not sell personal data in the common sense of the term.
  • Right to equal service and price even if you exercise privacy rights, as required by law.
  • Rights under GDPR/UK GDPR, including access, rectification, erasure, restriction, portability, and objection to certain processing.
  • Right to lodge complaints with your data-protection authority or other relevant regulator in your jurisdiction.

Ready when you are

See your care app, in your brand, before anyone signs anything.

Book a 30-minute call. We set up a working preview under your name, with sample people and sample notes, so a scheduler, a nurse, and a family member can try real workflows before you decide anything.