Skip to content

Security & Compliance

Security and compliance, built in

Tessera handles protected health information for some of the most heavily regulated care settings in the US. Access control, audit logging, exclusion screening and reporting deadlines aren’t bolted on — they’re part of how the product works every day.

HIPAA-aligned · BAA available · Designed for 42 CFR §483 and the Elder Justice Act

What we cover

The pillars of a compliant care platform

Each pillar maps to a real obligation care homes are held to — and each is enforced in the product, not promised in a policy document.

HIPAA-aligned data handling

Protected health information is access-controlled by facility and by role, encrypted in transit, and supported by audit controls designed to help you meet your HIPAA obligations. A Business Associate Agreement is available.

Audit-grade logging

Every create, update and delete on a clinical record is captured in a separate, append-only audit database — an immutable trail that records who changed what, and when.

Role-based access control

Six roles — care_assistant, senior_carer, nurse, manager, admin and family — scope what each person can see and do. Facility membership is enforced on the server, not just hidden in the UI.

Regulatory coverage

Built around 42 CFR §483, the Elder Justice Act reporting deadlines, and US state incident reporting — with a per-state mapping layer that produces inspection-ready exports.

Exclusion screening

OIG/SAM exclusion, state nurse-aide and abuse registry, and criminal background checks are tracked as first-class, expiry-aware credentials — with alerts before they lapse.

Data residency & hosting

Application data runs on US-hosted managed PostgreSQL, with the append-only audit log kept in an isolated logging database separate from the transactional core.

HIPAA program

How Tessera supports your HIPAA program

HIPAA compliance is a shared responsibility between you and your software. Tessera is designed to support the administrative, technical and physical safeguard themes of the Security Rule — it does not, on its own, guarantee that your organization is compliant.

A Business Associate Agreement (BAA) is available for customers handling PHI on the platform. Reach out through our contact page to start the conversation.

Administrative safeguards

  • Role-based access aligned to job function across six defined roles
  • Facility-membership checks enforced server-side on every clinical request
  • Audit controls that record creates, updates and deletes on clinical records
  • Workforce screening tracked as expiry-aware credentials (OIG/SAM, state registry, background)

Technical safeguards

  • Encryption of protected health information in transit
  • Authentication via Auth0 with JWTs validated on every request
  • Append-only audit trail held in a separate, isolated logging database
  • Least-privilege data access scoped to a user’s facilities and role

Physical & hosting safeguards

  • US-hosted managed PostgreSQL with provider-managed infrastructure controls
  • Logical separation of transactional data from the immutable audit log
  • Managed backups and recovery handled at the hosting layer
  • Production access restricted and reviewed as part of our operating practice

“Designed to support” describes capabilities the platform provides. Meeting HIPAA, 42 CFR §483 and state requirements also depends on how your organization configures and operates Tessera.

Responsible disclosure

Found something? Tell us.

Security is never finished. If you believe you’ve found a vulnerability in Tessera, we want to hear from you. Email us with the details and we’ll acknowledge your report, investigate, and keep you updated as we work to resolve it. Please give us a reasonable window to remediate before any public disclosure.

Talk to us about your compliance needs

We’ll walk through how Tessera handles PHI, access control, audit logging and reporting — and how a BAA fits your program.

No credit card required · Personalized walkthrough · Built around your workflows