Security and data protection
What CareMatch does to protect your caregivers' and clients' information, in plain English.
Sign-in
Every account uses multi-factor authentication, every time. There is no setting that turns it off for an individual account. Accounts are created only by an agency inviting a named person; nobody can sign themselves up.
Your data stays yours
Each agency's information is kept separate from every other agency's, and the separation is enforced by the database itself, not only by the application. A bug in the software is not enough to let one agency see another's caregivers, clients or visits.
Who can see what
Access inside an agency depends on role: administrators, schedulers, caregivers and clients each see what their job needs. Administrative actions are recorded in an audit log your agency can read and export.
Encryption and storage
Information is encrypted in transit and at rest. The database and file storage are encrypted, and file storage is closed to public access. CareMatch runs on Amazon Web Services.
Backups
Each agency's records are copied every night, and the copies are checked. If something goes badly wrong, there is something to restore.
What we store
For caregivers: name, address, phone, qualifications, availability and, if the agency adds one, a photo. For clients: name, address, phone, services received and the care instructions the agency writes. We do not store medical records. The full list is on the privacy page.
What we do not claim
CareMatch does not hold a security or compliance certification and does not claim to be HIPAA certified. If your agency has a specific requirement, ask before you sign up at support@carematchscheduler.com and we will tell you honestly what we can and cannot offer today.