HIPAA Compliance

Built for HIPAA from day one.

WardLens was designed for clinical environments where patient data protection isn't optional. Every layer of our platform — from video capture to cloud storage to staff access — is engineered for HIPAA compliance.

Last updated: April 19, 2026


Data Protection & Encryption

Body camera footage in clinical settings contains some of the most sensitive data in healthcare. We treat it that way.

🔒

Encryption at Rest

All video footage, audio recordings, transcriptions, and clinical notes are encrypted using AES-256 encryption at rest. Encryption keys are managed through a dedicated key management service with automatic rotation.

  • AES-256-GCM encryption standard
  • Dedicated key management with automatic rotation
  • Separate encryption keys per organization
  • Keys stored independently from encrypted data
🌐

Encryption in Transit

All data transmitted between devices, servers, and clients is protected with TLS 1.2+ encryption. No unencrypted data ever crosses the wire.

  • TLS 1.2/1.3 for all connections
  • Certificate pinning for device-to-server communication
  • HSTS enforced on all web endpoints
  • Forward secrecy with ECDHE key exchange
🛡

Infrastructure Security

WardLens runs on SOC 2 Type II certified cloud infrastructure with physical security controls, network isolation, and continuous monitoring.

  • SOC 2 Type II certified hosting environment
  • Network isolation between customer environments
  • DDoS protection and web application firewall
  • Regular penetration testing and vulnerability scanning
💾

Backup & Recovery

Automated encrypted backups ensure data durability. Recovery procedures are tested regularly to meet healthcare uptime requirements.

  • Daily automated encrypted backups
  • Point-in-time recovery capability
  • Cross-region backup replication
  • Documented disaster recovery procedures

Access Controls

Not everyone who works at a hospital should see body camera footage. WardLens enforces the principle of minimum necessary access at every level.

👤

Role-Based Access Control (RBAC)

Access to footage, clinical notes, and incident records is governed by configurable roles that map to your hospital's organizational structure.

  • Safety Director — Full access to incidents, footage review, and reporting
  • Clinical Reviewer — Access to clinical notes and transcriptions for review and approval
  • Department Manager — Access scoped to their department's incidents and footage
  • Staff Member — Can submit incident reports; limited footage access
📋

Audit Logging

Every access to protected health information is logged with an immutable audit trail. Who accessed what, when, and why — all traceable.

  • Immutable event logs on all data access
  • Login/logout tracking with session management
  • Footage viewing logged with timestamp and user identity
  • Clinical note review workflow fully audited
  • Exportable audit reports for compliance reviews
ℹ️

Minimum Necessary Standard. WardLens enforces HIPAA's minimum necessary standard by default. Users only see data relevant to their role and department. Accessing records outside your scope requires explicit authorization and is logged for audit.

Data Retention & Disposal

Healthcare data has strict retention requirements. WardLens gives you full control over how long data is kept and how it's destroyed.

Configurable Retention

Set retention periods per data type — video footage, clinical notes, incident records — based on your facility's policies and state requirements. Defaults align with common healthcare retention guidelines.

Automated Disposal

When retention periods expire, data is automatically queued for secure deletion. Deletion is cryptographic — encryption keys are destroyed, rendering data permanently unrecoverable.

Legal Hold Support

Place litigation holds on specific records to prevent automatic deletion during legal proceedings or investigations, without affecting the retention schedule for other data.

Patient Consent Workflows

Recording in clinical environments requires thoughtful consent processes. WardLens provides tools to document and manage patient consent at every stage.

How Consent Works in WardLens

WardLens supports a multi-layer consent approach designed for clinical realities — where patients may be conscious, unconscious, or in distress.

  • Facility-level notice: Signage and admissions documentation inform patients that body cameras may be in use for safety and documentation purposes
  • Verbal consent capture: Staff can record verbal consent at the start of an interaction; consent status is tagged to the footage record
  • Opt-out recording: If a patient declines recording, staff can pause or stop capture; the opt-out is documented in the system
  • Incapacitated patient protocol: When a patient cannot consent (unconscious, psychiatric emergency), facility policy governs recording; WardLens logs the clinical justification
  • Consent documentation: All consent decisions — granted, declined, or clinical override — are stored as immutable records attached to the footage

Breach Notification Procedures

In the event of a data breach involving protected health information, WardLens follows HIPAA Breach Notification Rule requirements.

Our Commitment

As a Business Associate, WardLens will notify covered entities of any breach of unsecured protected health information without unreasonable delay, and no later than 60 days after discovery of the breach.

⚠️

Detection & Response

  • Automated anomaly detection for unauthorized access patterns
  • 24/7 security monitoring with alert escalation
  • Documented incident response plan tested annually
  • Designated security officer responsible for breach assessment
📢

Notification Process

  • Covered entity notified within 60 days of discovery
  • Notification includes: nature of breach, types of information involved, steps taken to mitigate, recommendations for affected individuals
  • Cooperation with covered entity's notification to HHS and affected individuals
  • Post-breach review and remediation documentation
📝

Business Associate Agreement. WardLens executes a BAA with every covered entity customer before any PHI is processed. Our BAA template is available for review at /baa. Contact us at wardlens@polsia.app to begin the BAA process.

Workforce Training & Policies

All WardLens personnel with access to protected health information receive HIPAA training upon hire and annually thereafter. Our internal policies cover:

We maintain documentation of all training completion and policy acknowledgments as required by HIPAA.

Ready to see WardLens in your environment?

We'll walk you through our security architecture, answer your compliance team's questions, and provide all documentation needed for vendor assessment.

Request a Compliance Review →