SOC 2 and HIPAA
How careCycle protects member data, and what backs the compliance posture your compliance team will ask about.
Medicare and ACA work means every call, text, and record in careCycle touches sensitive member information. careCycle is SOC 2 Type 2 certified and HIPAA compliant out of the box, and this page explains the concrete controls behind that posture, in the terms your compliance reviewer will ask about.
Access Control
- Role-based access with row-level scoping. Built-in roles (owner, admin, CSR, manager, agent) control what each person can view and edit per resource, and agents are scoped to their own customers by assignment and NPN, enforced on the server. Custom roles let you tighten further. See roles and visibility.
- Hard session limits. Sessions are capped at 12 hours from login, an absolute limit designed for HIPAA and SOC 2 expectations, so a forgotten open laptop does not stay authenticated indefinitely.
- Live-call monitoring is permission-gated. Listening in on or joining agent calls requires a dedicated softphone admin permission.
Audit Trails
Actions across the platform are written to an audit log with who, what, when, and from where: customer record changes, policy changes, campaign and enrollment actions, call actions, user administration, billing actions, notes, tasks, and bulk operations. Consent changes (do-not-call, opt-outs) are audited with their compliance context, and even automated writes, like a ping prefilling a customer record from vendor data, leave an audit entry marked as a system action.
Data Retention and Minimization
- Ten-year compliance archive. Platform logs are retained for ten years in a write-locked archive aligned to CMS Medicare record-keeping expectations. Records in the archive cannot be modified or deleted, even by administrators, outside a controlled break-glass process.
- PII is purged when it has no reason to persist. Vendor pings that never became calls have their personal data scrubbed after 72 hours. Consent evidence is stored separately from personal data precisely so purges can remove PII while preserving the compliance trail.
- Consent evidence is kept. Verbal opt-in recordings live on the customer record for audit purposes, and ping-post consent attestations (consent basis, timestamps, written-consent artifacts) are retained even when other ping data is purged.
Consent Integrity
Compliance flags behave as one-way doors: opt-outs cascade across channels (a do-not-text request also stops calls), re-imported lead files can tighten consent but never loosen it, and post-call analysis automatically catches verbal do-not-call requests. The full mechanics are on the TCPA Compliance page.
What This Means Practically
- Your E&O and carrier audits can lean on the audit log and the ten-year archive.
- Downline agents see only their own book, enforced by the platform, which is usually the first question FMO compliance teams ask.
- You do not need to build retention, suppression, or quiet-hours controls around careCycle. They are already inside it.
For security questionnaires, audit reports, or a BAA discussion, contact support@carecycle.ai and we will connect you with the right people.