Compliance is a working system, not a product badge.
iCare EVV LLC is intended to operate as a HIPAA Business Associate when applicable—when it provides services to a Covered Entity or another Business Associate and creates, receives, maintains, or transmits PHI on that organization’s behalf.
Draft — legal review required
- No “HIPAA certified” claim
- BAA evaluated case by case
- Shared operational responsibility
Draft — legal and compliance approval required
Proposed effective date: July 21, 2026 · Version 1.0. Ohio formation jurisdiction and authorized-representative approval remain outstanding.
Business Associate status depends on the actual service relationship
The status is not created merely because a customer uses iCare or enters health-related information. When HIPAA requires a Business Associate relationship, the parties must execute an appropriate BAA and any applicable service, privacy, security, or data-processing agreements.
Controls that support accountable use
Administrative
Role design, access review, incident response, workforce procedures, and vendor governance require organizational ownership.
Technical
Authenticated sessions, permissions, tenant scoping, audit history, and secure transport support protected workflows.
Operational
Configuration, device practice, data minimization, training, review queues, and escalation determine how controls work day to day.
Technology and organizational practice work together
iCare responsibilities
- Operate documented platform controls
- Protect platform access and tenant boundaries
- Maintain relevant activity and security capabilities
- Support agreed contractual and incident processes
Customer responsibilities
- Determine legal role and permitted use
- Assign and review appropriate access
- Configure workflows and retention for requirements
- Train the workforce and respond to operational risk
Business associate agreement
BAA availability is evaluated case by case. Send requests to support@icareevv.com.
No product certification claim
iCare does not claim that software itself is “HIPAA certified.” Compliance depends on platform safeguards, customer configuration, workforce practices, access controls, policies, training, and governing agreements.
Review the exact service and responsibility model.
Security, privacy, procurement, and legal questions should be evaluated against the configured service and governing agreements.
