Skip to content
BTBCare

Security & compliance

What protects your participants’ data, and what you can show a surveyor

BTBCare holds Medi-Cal numbers, diagnoses and medication records. This page lists the controls in the product, how signatures are made defensible, and the CBAS rules the record is kept against.

01 · Access

Who can get in, and when

Controls your administrator sets for the whole center.

Two-factor sign-in
Authenticator-app codes (TOTP). An administrator can require it for every account.
Sign-in hours
Limit sign-ins to the hours and days your center is open, in your time zone.
Idle sign-out
Sessions end after 30 minutes without activity. Session cookies are secure and HTTP-only.
Role permissions
Each role sees what its job needs, with per-person overrides. Whole-chart export is limited to administrators and supervisors.

02 · Data

How participant data is protected

Identifiers are encrypted, actions are logged, and records stay with their center.

Field-level encryption
The Medi-Cal CIN, Medicare number and SSN are encrypted with AES-256-GCM, with a fresh IV for every record.
Audit log
Sign-ins, changes, exports and signatures are written with who did it, when, and from what IP address and browser.
Center scoping
Every record belongs to a center, and staff only work with their own center’s participants.
Business Associate Agreement
We sign a BAA with every center before any participant data is loaded.

03 · Signatures

Electronic signatures built to hold up in an audit

A drawn signature image proves very little. In BTBCare the signature is the record of who signed, what they agreed to, exactly what they signed and when.

Identity
Signed from the signer’s own login, with their license or NPI recorded at the moment of signing.
Intent
The signer acknowledges an attestation statement. The exact wording is stored with the signature.
Content
A SHA-256 hash of exactly what was signed, so any later change is detectable.
Time
Server time, not the device clock. A backdated effective date is stored separately and logged.
Step-up
With two-factor on, signing asks for the code again, even mid-session.
Locking
Signed content can’t be edited. Changes create a new version that must be signed again. Revoking a signature is a status change, never a deletion.

Designed against

ESIGN Act (15 U.S.C. § 7001)California UETA (Civ. Code § 1633)CMS Program Integrity Manual, Ch. 3 § 3.3.2.4HIPAA Security Rule (45 CFR § 164.312)
Signature recordappend-only
Document
DHCS 0020 · M. Okafor · version 3
Signed by
J. Park, RN (license on file)
Attested
“I reviewed this plan of care and agree with the nursing goals.”
Content
sha256 3f9a61c0…7d4ee2b7
Time
Oct 8, 2026 · 10:42:18 AM PT (server)
Verified
Password + authenticator code

04 · CBAS compliance

The record is kept against the rules you are surveyed on

Deadlines, required signers and reporting clocks are tracked as people work, not rebuilt before a visit.

Title 22 timelines
Day 1, Day 30 and six-month reassessments per participant (CCR Title 22 § 54341), with change in condition handled under § 54319.
The DHCS 0020
A completeness check before it goes to the plan, and every required discipline signs, including behavioral health when the diagnosis calls for it.
Unusual occurrences
Likely reportable incidents are flagged with the 24-hour DHCS deadline, and the report time and reference are recorded.
State forms and reports
CDA 7000 participation agreement (§ 54217), CACFP 52 and the MSSR, generated from the record.
Care gaps
Overdue assessments, goals with no interventions, expiring authorizations, missing documents and stale medication reviews.
Audit packets
A participant’s full chart as a ZIP of originals or a merged PDF. The export is logged as a disclosure.
Audit packet · M. OkaforZIP or PDF
  • 00 cover and manifest.pdf1 file
  • care plans3 files
  • ipc 00202 files
  • assessments14 files
  • medications6 files
  • signatures and audit1 file

Export logged as a disclosure · Oct 8, 3:05 PM · A. Rivera

05 · Shared responsibility

The part only your center can do

No software makes a center HIPAA compliant on its own. BTBCare gives you the controls; your policies decide how they are used: who gets which role, whether two-factor is required for everyone, what your sign-in hours are, and how quickly a departing employee’s account is turned off.

We help you set those up during onboarding, and we will answer your security questionnaire or your auditor’s questions directly. Write to [email protected].

See it with your own roster

Forty-five minutes on a call, using your payers, your departments and the parts of the week that take the longest. Bring your biller.