A BAA comes first
We sign a BAA with your agency before CareSwift for Agencies processes PHI. PHI is handled only within an approved agency deployment.
CareSwift for Agencies is HIPAA compliant for approved agency deployments. We sign a BAA before processing PHI.
Providers work in a separate CareSwift environment provisioned for your agency. They finalize the narrative and copy it into your existing ePCR. CareSwift has no integration with your ePCR.
Trust Center destination confirmed. CareSwift for Agencies scope and applicable evidence remain pending under D4.
Applies to CareSwift for Agencies · Last reviewed July 18, 2026
We sign a BAA with your agency before CareSwift for Agencies processes PHI. PHI is handled only within an approved agency deployment.
Providers work on the narrative they are currently completing. Supervisors and administrators can view finalized narratives within their assigned scope. Your agency selects an approved retention preset.
CareSwift helps clarify information and drafts editable narratives. Providers confirm or change suggested information, review the draft, and remain responsible for what they finalize. CareSwift does not make clinical decisions or certify that a narrative is clinically complete.
Providers copy the finalized narrative into your existing ePCR. CareSwift does not write to, synchronize with, or submit to your ePCR and has no visibility into what happens there afterward.
An authorized provider enters the information needed for the narrative in your agency's CareSwift environment. CareSwift asks for clarification when something appears missing or unclear, then creates an editable narrative from information the provider supplied or confirmed. The provider reviews and finalizes it, then copies it into your ePCR.
Conceptual product flow for low-fidelity review. This is not deployed architecture or implementation evidence.
The provider selects the call type and enters the key facts: what happened, what they found, what they did, and the disposition. CareSwift shows the questions your agency has configured for that kind of call.
CareSwift asks a focused follow-up when something needed for the narrative appears missing or unclear. Suggested information must be confirmed or changed by the provider.
CareSwift creates a draft using provider-supplied or provider-confirmed information and your agency's writing rules.
The provider checks the facts, edits the narrative as needed, and finalizes it.
The provider copies the finalized narrative into the agency's existing ePCR.
CareSwift does not read from, write to, synchronize with, or submit to your ePCR. Once the narrative is copied, CareSwift cannot see what happens there or confirm that the chart was completed or submitted.
CareSwift records the call details and answers the provider supplies, clarification and confirmation history, narrative drafts and finalized versions, revisions made before the workflow closes, and relevant CareSwift workflow events. The following sections explain who can access that information and how long it is retained.
Providers can see the narrative they are currently working on. Once they finalize it, copy it into the ePCR, and leave the workflow, they do not have access to a browsable history of finalized agency narratives.
Authorized supervisors and administrators can read finalized narratives within their assigned scope, but they cannot change what the provider wrote.
Can create, review, edit, finalize, and copy the narrative they are currently completing. Providers do not have ongoing access to narratives from prior workflows or shifts.
Can read finalized narratives and view workflow analytics for the teams, stations, and units they oversee. Supervisors cannot edit provider narratives.
Can read finalized narratives and view analytics across the organization. Administrators also manage people, roles, team assignments, units, and approved agency settings. They cannot edit provider narratives.
We configure your forms, questions, and writing rules using synthetic or non-PHI test information. That work does not require ongoing access to production PHI.
CareSwift support has no access to PHI by default. If PHI access is necessary to troubleshoot an issue, your agency must approve it first. Access is limited in time, the reason is recorded, and the activity is audited.
Draft narrative text is visible only to the provider completing it. Supervisors and administrators can see overall workflow progress, but they cannot open an unfinished narrative.
Supervisor and administrator access is read-only. CareSwift does not include a manager approval, correction, or send-back queue. Corrections after the handoff are handled through the agency's existing ePCR process.
CareSwift uses AI to identify information that may need clarification and to create an editable narrative from information the provider supplies or confirms. The provider reviews, edits, and remains responsible for the narrative they finalize.
Your agency selects a 30-day, 90-day, or 365-day retention preset during contracting and onboarding. The selected period begins when a narrative is finalized and applies to finalized narratives, the answers and clarification history behind them, and related CareSwift workflow activity.
30
Minimum retention
90
Standard retention
CareSwift default after D3/D4 verification
365
Extended review
An unfinished draft is deleted after seven days of inactivity.
If a provider leaves your agency or should no longer have access, the agency administrator deactivates their membership and their CareSwift access ends.
Removing a provider does not delete agency-controlled information. Authorized supervisors and administrators can continue to view finalized narratives within their assigned scope until the selected retention period ends.
CareSwift is a separate narrative workflow. Operational fallback, incident response, and agency exit each follow a defined path.
CareSwift is online-only. If it is unavailable, providers return to your agency's normal ePCR documentation process. CareSwift does not complete or submit ePCR charts.
CareSwift follows its documented incident-response process and any notification obligations established by applicable law, the BAA, and your agreement.
Supporting incident-response, recovery, and continuity materials are available to authorized reviewers through our Trust Center or security review.
When your agreement ends, any contractually required return or support-assisted export of agency information and subsequent deletion follow the applicable agreement, BAA, and legal requirements.
The exact process and timelines are established during contracting and security review.
Before providers use CareSwift with PHI, CareSwift and your agency complete a defined launch process. We prepare and test the agency environment, while your team supplies the decisions, information, and approvals needed for live use.
This page explains the product-specific practices of CareSwift for Agencies. Our Vanta-hosted Trust Center provides CareSwift's current published security and compliance information.
Review the Trust CenterTrust Center destination confirmed. CareSwift for Agencies scope and applicable evidence remain pending under D4.
Email contact@careswift.com. Please do not include PHI, report content, or other sensitive patient information in your message. If protected information is required for an authorized review, CareSwift will provide a secure process.
The applicable agreement and BAA govern the binding obligations for your agency's deployment.
Evaluating CareSwift for your agency? Book a 20-minute demo.