Privacy Policy
Effective date: January 1, 2026 · Last updated: July 18, 2026
1. Introduction
CareVieo ("CareVieo," "we," "us," or "our") is a cloud-based healthcare operations platform that provides scheduling, Electronic Visit Verification (EVV), credential management, CRM, billing, caregiver management, patient and family portals, secure communications, and related services to home care, home health, hospice, private duty, behavioral health, and other healthcare organizations throughout the United States.
This Privacy Policy explains what information we collect, how we use it, when we share it, and the choices you have. It applies to carevieo.com, the CareVieo web and mobile applications, and related services (collectively, the "Service").
2. Information we collect
Depending on how you use the Service, we may collect:
- Personal information — name, email, phone number, mailing address, date of birth, government ID (for identity/credentialing).
- Organization information — agency name, tax ID, licenses, service locations, staff roster, billing details.
- Caregiver information — role, credentials, certifications, background checks, training records, availability, timesheets, electronic signatures.
- Patient / client information — demographics, care plans, authorizations, service notes, tasks, and other Protected Health Information ("PHI") uploaded by your agency.
- Employment information — I-9, W-4, direct deposit, and other onboarding records agencies upload.
- Device information — device model, operating system, app version, push tokens, mobile identifiers.
- Browser information — browser type and version, language, referring pages, session identifiers.
- IP address — used for security, fraud prevention, audit logging, and coarse geolocation.
- Location information — precise GPS coordinates during EVV clock-in / clock-out, and geofence entry/exit events, when enabled by your agency.
- Uploaded documents — care plans, assessments, consents, driver's licenses, credentials, photos, and other files you upload.
- Credential documents — certifications, licenses, immunization records, background checks, and expiration dates.
- Electronic signatures — captured on device (finger, stylus, or mouse) for consents, timesheets, and required forms.
- Communication records — SMS, email, in-app messages, and call metadata sent through the Service.
- Support requests — the content of your messages to support, including attachments.
- Usage analytics — pages viewed, features used, actions taken, error diagnostics.
- Cookies — see the Cookies section below.
3. HIPAA and protected health information
CareVieo is designed to support HIPAA-compliant workflows. When we process PHI on behalf of a covered entity or business associate, we act as a technology provider and Business Associate under a signed Business Associate Agreement ("BAA"). The healthcare organization (the "Covered Entity" or upstream "Business Associate") remains responsible for its own HIPAA compliance, including obtaining patient authorizations and setting appropriate use and disclosure practices.
- PHI is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access is role-based and least-privilege.
- All access to PHI is recorded in tamper-evident audit logs.
- Breach notification is performed as required by HIPAA and the BAA.
See our HIPAA & BAA page for more.
4. SMS / text message communications
CareVieo uses Twilio to deliver text messages. Users may opt in to receive SMS messages related to the Service, including:
- Appointment and visit reminders
- Visit start / end notifications
- Schedule changes and open shift offers
- Caregiver notifications (assignments, credential renewals)
- Account alerts (sign-in, password reset, security)
- Billing notifications (invoices, payment receipts, past-due notices)
- Two-factor authentication codes
- Other service-related communications you request
Standard SMS program terms:
- Message frequency varies based on your account activity.
- Message and data rates may apply.
- Reply STOP to any message to unsubscribe from that SMS program.
- Reply HELP for assistance, or contact support@carevieo.com.
- Consent to receive SMS is not a condition of receiving healthcare services or using CareVieo.
- Carriers are not liable for delayed or undelivered messages.
5. SMS messaging privacy
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors that support the Service (such as customer service platforms and messaging providers) is permitted only to provide the requested services. Text messaging originator opt-in data and consent will not be shared with any third parties, except as required to deliver messaging services or to comply with applicable law.
6. Email communications
We send transactional emails (account confirmations, password resets, invoices, visit notifications, credential expirations, and other service-related messages) to the address on file. These are required for the operation of the Service and cannot be unsubscribed while your account is active.
We may also send marketing emails (product news, tips, event invitations) to administrators who have opted in. Every marketing email includes an unsubscribe link; you can also email privacy@carevieo.com to opt out.
7. Cookies and tracking
- Necessary cookies — required for sign-in, session security, and CSRF protection.
- Analytics cookies — help us understand product usage in aggregate so we can improve the Service.
- Preference cookies — remember your theme, tenant, and display settings.
- Marketing cookies — may be used in the future on our marketing site only; if introduced, we will provide a cookie banner and preference controls.
Most browsers let you refuse or delete cookies; doing so may affect Service functionality.
8. How we use information
- Scheduling, EVV, and care coordination
- Billing, invoicing, and payment processing
- Compliance monitoring (state, payer, HIPAA, EVV)
- Credential verification and expiration alerts
- Customer support and troubleshooting
- Platform improvements and product analytics
- Security, fraud prevention, and abuse detection
- Regulatory and legal compliance
9. How we share information
CareVieo does not sell personal information. We share information only with:
- Authorized healthcare organizations — the agency you belong to and its authorized users.
- Business Associates and subprocessors — hosting, storage, and infrastructure providers under written contracts.
- Payment processors — Stripe for subscription and invoice payments.
- SMS provider — Twilio for text message delivery.
- Email provider — for transactional and marketing email delivery.
- Government agencies — when legally required (subpoena, court order, HIPAA-required disclosure).
10. Data security
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Multi-factor authentication (MFA) enforced for all users.
- Role-based access controls and least-privilege by default.
- Tamper-evident audit logs for PHI access.
- Automated encrypted backups with point-in-time recovery.
- 24/7 security monitoring and vulnerability management.
- HIPAA administrative, physical, and technical safeguards.
- SOC 2 controls in progress.
11. Data retention
- Healthcare records — retained for the term of your agency's subscription plus a 30-day export grace period, then deleted unless a longer retention period is required by law or the BAA.
- Credential documents — retained for the duration of employment plus applicable state retention periods.
- Audit logs — retained for at least 6 years, per HIPAA.
- User accounts — retained while active; inactive accounts may be deprovisioned by the agency.
- Backups — encrypted backups are retained on a rolling window (typically 30 days).
12. Your rights and choices
- Access — request a copy of the personal information we hold about you.
- Correction — update inaccurate information (most fields are editable in-product).
- Deletion — request deletion where legally allowed; PHI is deleted per the agency's instructions and the BAA.
- Export — export your data in a portable format.
- Marketing opt-out — unsubscribe at any time.
- SMS opt-out — reply STOP or contact support.
- Cookie preferences — controlled via your browser or, where offered, our cookie banner.
Email privacy@carevieo.com to exercise any right.
13. Children's privacy
The Service is not intended for children under 13, and we do not knowingly collect data from children under 13 as end users. Pediatric client records uploaded by agencies are processed as PHI under the BAA.
14. Changes to this policy
We will post any changes to this policy on this page and update the "Last updated" date. Material changes will be communicated to administrators by email at least 30 days before they take effect.
15. Contact us
CareVieo
Email: privacy@carevieo.com
Support: support@carevieo.com
Web: https://carevieo.com
