Trust, Privacy, and HIPAA Compliance at Cedar Health
Remote Patient Monitoring and Chronic Care Management depend on handling sensitive health information every day. This page explains the safeguards Cedar Health applies to protect patients, practices, and the data that moves between them.
How We Protect Health Information
HIPAA Compliance
Cedar Health operates as a Business Associate under HIPAA. We sign a Business Associate Agreement with every partner practice and follow the Privacy, Security, and Breach Notification Rules across all Remote Patient Monitoring and Chronic Care Management workflows.
Encryption In Transit and At Rest
Protected health information is encrypted in transit with TLS and at rest with industry standard encryption. Device readings travel over secured connections from the patient home to the care team dashboard.
Role Based Access Control
Access to patient records follows the minimum necessary standard. Staff permissions are scoped by role, reviewed regularly, and revoked promptly when a role changes.
Audit Logging and Monitoring
System activity is logged and monitored so every access to protected health information can be traced, reviewed, and investigated when needed.
Vendor and Infrastructure Review
Infrastructure and subprocessors are reviewed for security posture and covered by agreements that carry HIPAA obligations forward. Patient data is never used to train public AI models.
Certifications
Current certification and attestation status: [INSERT ACCURATE CERTIFICATION STATUS, for example HITRUST or SOC 2 Type II, including audit date].

Read our full HIPAA Notice of Privacy Practices and Privacy Policy.
Cedar Health at a Glance
The figures below are reserved for verified company data. Replace each placeholder with a confirmed number before publishing.
[INSERT ACCURATE NUMBER]
Years in operation
[INSERT ACCURATE NUMBER]
Patients served
[INSERT ACCURATE NUMBER]
Partner providers and clinics
[INSERT VERIFIED OUTCOME METRIC]
Measured clinical outcome
What Partner Practices Say
[INSERT APPROVED CLIENT QUOTE]
[INSERT APPROVED CLIENT QUOTE]
Security and Compliance Questions
Is Cedar Health HIPAA compliant?
Yes. Cedar Health operates as a HIPAA Business Associate, signs a Business Associate Agreement with each partner practice, and applies administrative, physical, and technical safeguards to all protected health information it handles.
Where is patient data stored and how long is it kept?
Patient data is stored in access controlled, encrypted systems within the United States and retained for six years in line with HIPAA documentation requirements unless a practice agreement specifies otherwise.
Is patient data used to train artificial intelligence models?
No. Protected health information is never used to train public or third party artificial intelligence models.
Who can access patient information at Cedar Health?
Only authorized clinical and support staff whose role requires it, under the HIPAA minimum necessary standard, with access logged and reviewed.