Security, data, and AI practices

CareSwift for Agencies is HIPAA compliant for approved agency deployments. We sign a BAA before processing PHI.

Providers work in a separate CareSwift environment provisioned for your agency. They finalize the narrative and copy it into your existing ePCR. CareSwift has no integration with your ePCR.

Trust Center destination confirmed. CareSwift for Agencies scope and applicable evidence remain pending under D4.

Applies to CareSwift for Agencies · Last reviewed July 18, 2026

At a glance

A BAA comes first

We sign a BAA with your agency before CareSwift for Agencies processes PHI. PHI is handled only within an approved agency deployment.

Role-scoped access. Agency-selected retention.

Providers work on the narrative they are currently completing. Supervisors and administrators can view finalized narratives within their assigned scope. Your agency selects an approved retention preset.

AI assists. Providers remain responsible.

CareSwift helps clarify information and drafts editable narratives. Providers confirm or change suggested information, review the draft, and remain responsible for what they finalize. CareSwift does not make clinical decisions or certify that a narrative is clinically complete.

Copy and paste, not an integration

Providers copy the finalized narrative into your existing ePCR. CareSwift does not write to, synchronize with, or submit to your ePCR and has no visibility into what happens there afterward.

What happens from provider input to your ePCR?

An authorized provider enters the information needed for the narrative in your agency's CareSwift environment. CareSwift asks for clarification when something appears missing or unclear, then creates an editable narrative from information the provider supplied or confirmed. The provider reviews and finalizes it, then copies it into your ePCR.

Conceptual product flow for low-fidelity review. This is not deployed architecture or implementation evidence.

Inside your agency's CareSwift environment
1

Enter the call details

The provider selects the call type and enters the key facts: what happened, what they found, what they did, and the disposition. CareSwift shows the questions your agency has configured for that kind of call.

2

Clarify what needs attention

CareSwift asks a focused follow-up when something needed for the narrative appears missing or unclear. Suggested information must be confirmed or changed by the provider.

3

Create an editable narrative

CareSwift creates a draft using provider-supplied or provider-confirmed information and your agency's writing rules.

4

Review and finalize

The provider checks the facts, edits the narrative as needed, and finalizes it.

Copy and paste

Your existing ePCR

The provider copies the finalized narrative into the agency's existing ePCR.

CareSwift stops at copy and paste

CareSwift does not read from, write to, synchronize with, or submit to your ePCR. Once the narrative is copied, CareSwift cannot see what happens there or confirm that the chart was completed or submitted.

What information does CareSwift record during this flow?

CareSwift records the call details and answers the provider supplies, clarification and confirmation history, narrative drafts and finalized versions, revisions made before the workflow closes, and relevant CareSwift workflow events. The following sections explain who can access that information and how long it is retained.

Who can see agency narratives?

Providers can see the narrative they are currently working on. Once they finalize it, copy it into the ePCR, and leave the workflow, they do not have access to a browsable history of finalized agency narratives.

Authorized supervisors and administrators can read finalized narratives within their assigned scope, but they cannot change what the provider wrote.

Provider

Can create, review, edit, finalize, and copy the narrative they are currently completing. Providers do not have ongoing access to narratives from prior workflows or shifts.

Supervisor

Can read finalized narratives and view workflow analytics for the teams, stations, and units they oversee. Supervisors cannot edit provider narratives.

Agency administrator

Can read finalized narratives and view analytics across the organization. Administrators also manage people, roles, team assignments, units, and approved agency settings. They cannot edit provider narratives.

CareSwift's own access

We configure your forms, questions, and writing rules using synthetic or non-PHI test information. That work does not require ongoing access to production PHI.

CareSwift support has no access to PHI by default. If PHI access is necessary to troubleshoot an issue, your agency must approve it first. Access is limited in time, the reason is recorded, and the activity is audited.

What about drafts?

Draft narrative text is visible only to the provider completing it. Supervisors and administrators can see overall workflow progress, but they cannot open an unfinished narrative.

What if a supervisor spots a problem?

Supervisor and administrator access is read-only. CareSwift does not include a manager approval, correction, or send-back queue. Corrections after the handoff are handled through the agency's existing ePCR process.

How does CareSwift use AI, and what are its limits?

CareSwift uses AI to identify information that may need clarification and to create an editable narrative from information the provider supplies or confirms. The provider reviews, edits, and remains responsible for the narrative they finalize.

What CareSwift assists with

  • Identifying information that may be missing or unclear
  • Asking focused clarification questions
  • Creating an editable narrative using provider-supplied or provider-confirmed information and your agency's writing rules

What remains with the provider

  • Confirming or changing suggested information before it is treated as an answer
  • Verifying the facts and editing the narrative as needed
  • Affirming and finalizing the narrative
  • Deciding what is copied into the ePCR

How long is narrative information kept, and what happens when a provider leaves?

Your agency selects a 30-day, 90-day, or 365-day retention preset during contracting and onboarding. The selected period begins when a narrative is finalized and applies to finalized narratives, the answers and clarification history behind them, and related CareSwift workflow activity.

30

days

Minimum retention

90

days

Standard retention
CareSwift default after D3/D4 verification

365

days

Extended review

What happens to unfinished drafts?

An unfinished draft is deleted after seven days of inactivity.

What happens when a provider leaves?

If a provider leaves your agency or should no longer have access, the agency administrator deactivates their membership and their CareSwift access ends.

Removing a provider does not delete agency-controlled information. Authorized supervisors and administrators can continue to view finalized narratives within their assigned scope until the selected retention period ends.

What happens if CareSwift is unavailable, a security incident occurs, or your agency stops using it?

CareSwift is a separate narrative workflow. Operational fallback, incident response, and agency exit each follow a defined path.

If CareSwift is unavailable

CareSwift is online-only. If it is unavailable, providers return to your agency's normal ePCR documentation process. CareSwift does not complete or submit ePCR charts.

If a security or privacy incident occurs

CareSwift follows its documented incident-response process and any notification obligations established by applicable law, the BAA, and your agreement.

Supporting incident-response, recovery, and continuity materials are available to authorized reviewers through our Trust Center or security review.

If your agency stops using CareSwift

When your agreement ends, any contractually required return or support-assisted export of agency information and subsequent deletion follow the applicable agreement, BAA, and legal requirements.

The exact process and timelines are established during contracting and security review.

What happens before your agency goes live?

Before providers use CareSwift with PHI, CareSwift and your agency complete a defined launch process. We prepare and test the agency environment, while your team supplies the decisions, information, and approvals needed for live use.

CareSwift prepares

  • Provides the materials needed for contracting, the BAA, and your security review.
  • Provisions your agency environment and configures the approved call types, essential details, questions, follow-up rules, and narrative writing rules.
  • Sets up the initial roster, roles, teams, stations, and units using information your agency provides.
  • Tests the configured workflow and copy-and-paste handoff with synthetic or non-PHI information in each ePCR, browser, and device setup included in your deployment.
  • Trains administrators and supervisors, provides provider quick-start training, and supports the initial launch.

Your agency confirms

  • Names an agency owner and completes contracting, the BAA, and security review.
  • Supplies the initial roster, role assignments, teams, stations, units, and technical setups included in the deployment.
  • Selects a retention preset and approves the workflow CareSwift configures.
  • Participates in testing and training, then approves the configured workflow for live use.

Need supporting security or compliance information?

This page explains the product-specific practices of CareSwift for Agencies. Our Vanta-hosted Trust Center provides CareSwift's current published security and compliance information.

Review the Trust Center

Trust Center destination confirmed. CareSwift for Agencies scope and applicable evidence remain pending under D4.

Have a security or evidence question?

Email contact@careswift.com. Please do not include PHI, report content, or other sensitive patient information in your message. If protected information is required for an authorized review, CareSwift will provide a secure process.

The applicable agreement and BAA govern the binding obligations for your agency's deployment.

Evaluating CareSwift for your agency? Book a 20-minute demo.