Security at Infiniti Solution
Your agency's data and your patients' information deserve the highest level of protection. Here's exactly how we keep it safe.
Our Security Practices
Data Encryption
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. This includes all patient records, EVV logs, and billing data stored on our servers.
HIPAA Compliance
We operate as a HIPAA Business Associate and sign a Business Associate Agreement (BAA) with every agency client. PHI is handled under strict access controls with full audit logging.
Minnesota 245D Alignment
Our platform is built around Minnesota's 245D licensing requirements, including EVV mandate compliance, DHS-approved data formats, and secure record retention for the required 7-year period.
Role-Based Access Control
Every user has a defined role (Admin, Coordinator, Caregiver, Billing). Access is limited to only the data necessary for that role. Admins can customize permissions at the agency level.
Multi-Factor Authentication
MFA is available for all accounts and required for Admin-level users. We support authenticator apps and SMS-based verification to protect against unauthorized access.
EVV GPS Security
Location data collected for Electronic Visit Verification is transmitted over encrypted channels, stored securely, and only accessible to authorized agency staff and state systems.
Audit Logs
Every action taken in the platform is logged — login events, record changes, exports, and billing submissions. Audit logs are tamper-resistant and retained per regulatory requirements.
Cloud Infrastructure
Infiniti Solution is hosted on enterprise-grade cloud infrastructure with 99.9% uptime SLA, automated failover, and geographically redundant backups performed daily.
Incident Response
We maintain a documented incident response plan. In the event of a data breach, affected clients are notified within 60 days as required by HIPAA, and remediation steps are taken immediately.
Security Testing
Our platform undergoes regular vulnerability assessments and penetration testing. We follow OWASP guidelines and remediate identified vulnerabilities on a priority basis.
Business Associate Agreement (BAA)
Every Infiniti Solution agency client receives a signed HIPAA Business Associate Agreement before processing any Protected Health Information. The BAA outlines our responsibilities, data handling procedures, and breach notification obligations.
To request a copy of our BAA or to discuss security requirements for your agency, contact us directly.
Responsible Disclosure
We take all security reports seriously. If you discover a vulnerability in our platform, please report it to us responsibly before public disclosure.
Security Team
Email: security@infinitisolution.org
We will acknowledge your report within 48 hours and provide a remediation timeline.
Questions about security?
Our team is happy to walk you through our security posture and answer any compliance questions.
Talk to Us →