Carepassage

Built for healthcare. Built for trust.

Carepassage signs a BAA with every program and organization it works with. We collect only what is needed to book travel and leave a record of the stay, and we handle patient data like patient data, not like a guest reservation.

Three commitments we make on patient data

Where you are a Covered Entity, we are your Business Associate; where your program sits outside HIPAA, we sign the same agreement anyway and hold ourselves to it. Onboarding does not move to live patients until it is in place, and it is handled at setup rather than before the demo.

Why we sign a BAA when the hotel list on your website never needed one

When a patient books off the travel guide on your site today, the hotel sees a guest name, dates and a card. It never sees which program the patient is in, which site they are visiting, or the date of the visit. In the hotel’s hands that is an ordinary reservation, and nothing about it comes back to you.

Carepassage is different because we hold the linkage: the booking sits next to the visit, the site and the patient, which is what makes the page in your name, the five emails and the record by site possible. The cost is that we are a Business Associate, and we limit what flows to our hotel partner to the fields a hotel would see from any booking, never the medical context.

Common questions

Are you SOC 2 or HITRUST certified?

Not yet. This page describes operational practice today, not certifications we do not hold. SOC 2 Type I is on the roadmap as we scale. We are transparent about what we do and do not claim so your compliance team can evaluate honestly.

What does a hotel partner actually see?

Only the fields equivalent to a regular consumer reservation: guest name, dates, room type, and a payment token. No procedure, no patient or member ID, no program or plan, and no facility identifier flagged as medical. Free-text remarks are sanitized server-side before any vendor call.

How do we start a BAA review?

See your own patient page first, recorded or live. When you are ready, send us your BAA template or take ours, and we counter-sign before any patient data flows. Our Data Processing Addendum is published so your compliance officer can review subprocessors and security measures up front.

Related