CareFWD’s guiding principle is that finding where a patient can go should not require sharing who the patient is. This page is written for hospital IT and compliance reviewers; it says what we hold, what we don’t, and how to verify it.
A care routing network for hospital discharge planners: the step before a referral. A planner posts an anonymous Care Transition Query, matching post-acute providers answer whether they can take the case, and the planner chooses. The referral itself, with the patient’s identity, then happens in your existing systems.
| Data | Held? | Notes |
|---|---|---|
| Patient identity (name, date of birth, MRN, SSN, address, phone) | No | There is no field for it. Identifier-shaped text is blocked at entry and again server-side. |
| Care Transition Query | Yes, anonymous | Care category, destination ZIP, payer type, free-text needs. No patient identity. |
| Care manager and provider accounts | Yes | Name, work email, title, role, organization. Passwords are handled and hashed by the authentication provider and are never stored by CareFWD. |
| Facility and provider business data | Yes | Public business information: address, phone, fax, website, NPI, CMS rating. |
| Clinical records, referral packets, insurance member IDs | No | These stay in your hospital's referral workflow and systems. |
A routing query carries only non-identifiable details and is not intended to hold PHI.
The composer blocks common identifiers and discourages identifying free text before a query is ever sent. The same screen runs again on the server before anything is stored.
Providers don't see the patient or the care manager; the query stands alone.
Contact and clinical detail move only after a provider is chosen — through your hospital's existing HIPAA-compliant referral process, not through CareFWD.
We collect only what routing requires and keep resulting insights non-identifiable.
CareFWD is architected so that no protected health information is stored or transmitted through the platform. We do not currently hold a SOC 2 report. Our controls are aligned to the SOC 2 Trust Services Criteria and the HIPAA Security Rule safeguards, and a SOC 2 audit is planned as customer volume grows. We will complete your vendor security questionnaire (SIG Lite, HECVAT or your own form) and will sign a Business Associate Agreement if your review determines one is required.
Every third party that touches CareFWD data, and why.
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Application hosting, DNS, TLS, DDoS mitigation, inbound email routing | Global edge; US-based company |
| Supabase | PostgreSQL database, authentication, file storage | AWS ca-central-1 (Montréal, Canada) |
| Google Analytics 4 | Visit counts on public marketing pages only; never inside the portals | United States |
| Google Maps Platform (Places) | Server-side lookup of facility business details | United States |
| CMS.gov and NPPES (public datasets) | Provider ratings and NPI validation; outbound reads only | United States |
Write to security@care-fwd.com. We acknowledge reports within two business days. If we confirm an incident affecting your organization’s data, we will notify you within 72 hours of confirmation, with what happened, what was affected and what we are doing about it.
Not an EHR, not a PHI-carrying referral system, and not a payer directory: CareFWD is the patient-first decision step ahead of them.
Send your IT or InfoSec contact this page or the PDF. We will answer their questionnaire and walk your compliance stakeholders through the details.