Security & Compliance
Security and compliance, built in
Tessera handles protected health information for some of the most heavily regulated care settings in the US. Access control, audit logging, exclusion screening and reporting deadlines aren’t bolted on — they’re part of how the product works every day.
HIPAA-aligned · BAA available · Designed for 42 CFR §483 and the Elder Justice Act
What we cover
The pillars of a compliant care platform
Each pillar maps to a real obligation care homes are held to — and each is enforced in the product, not promised in a policy document.
HIPAA-aligned data handling
Protected health information is access-controlled by facility and by role, encrypted in transit, and supported by audit controls designed to help you meet your HIPAA obligations. A Business Associate Agreement is available.
Audit-grade logging
Every create, update and delete on a clinical record is captured in a separate, append-only audit database — an immutable trail that records who changed what, and when.
Role-based access control
Six roles — care_assistant, senior_carer, nurse, manager, admin and family — scope what each person can see and do. Facility membership is enforced on the server, not just hidden in the UI.
Regulatory coverage
Built around 42 CFR §483, the Elder Justice Act reporting deadlines, and US state incident reporting — with a per-state mapping layer that produces inspection-ready exports.
Exclusion screening
OIG/SAM exclusion, state nurse-aide and abuse registry, and criminal background checks are tracked as first-class, expiry-aware credentials — with alerts before they lapse.
Data residency & hosting
Application data runs on US-hosted managed PostgreSQL, with the append-only audit log kept in an isolated logging database separate from the transactional core.
HIPAA program
How Tessera supports your HIPAA program
HIPAA compliance is a shared responsibility between you and your software. Tessera is designed to support the administrative, technical and physical safeguard themes of the Security Rule — it does not, on its own, guarantee that your organization is compliant.
A Business Associate Agreement (BAA) is available for customers handling PHI on the platform. Reach out through our contact page to start the conversation.
Administrative safeguards
- Role-based access aligned to job function across six defined roles
- Facility-membership checks enforced server-side on every clinical request
- Audit controls that record creates, updates and deletes on clinical records
- Workforce screening tracked as expiry-aware credentials (OIG/SAM, state registry, background)
Technical safeguards
- Encryption of protected health information in transit
- Authentication via Auth0 with JWTs validated on every request
- Append-only audit trail held in a separate, isolated logging database
- Least-privilege data access scoped to a user’s facilities and role
Physical & hosting safeguards
- US-hosted managed PostgreSQL with provider-managed infrastructure controls
- Logical separation of transactional data from the immutable audit log
- Managed backups and recovery handled at the hosting layer
- Production access restricted and reviewed as part of our operating practice
“Designed to support” describes capabilities the platform provides. Meeting HIPAA, 42 CFR §483 and state requirements also depends on how your organization configures and operates Tessera.
Responsible disclosure
Found something? Tell us.
Security is never finished. If you believe you’ve found a vulnerability in Tessera, we want to hear from you. Email us with the details and we’ll acknowledge your report, investigate, and keep you updated as we work to resolve it. Please give us a reasonable window to remediate before any public disclosure.
Talk to us about your compliance needs
We’ll walk through how Tessera handles PHI, access control, audit logging and reporting — and how a BAA fits your program.
No credit card required · Personalized walkthrough · Built around your workflows