← Back to Home

Security at Infiniti Solution

Your agency's data and your patients' information deserve the highest level of protection. Here's exactly how we keep it safe.

HIPAA-conscious design Built for 245D providers AES-256 Encryption TLS 1.2+ In Transit EVV-ready workflows High-availability hosting

Our Security Practices

Data Encryption

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. This includes all patient records, EVV logs, and billing data stored on our servers.

HIPAA Compliance

We operate as a HIPAA Business Associate and sign a Business Associate Agreement (BAA) with every agency client. PHI is handled under strict access controls with full audit logging.

Minnesota 245D Alignment

Our platform is built around Minnesota's 245D licensing requirements, including EVV mandate compliance, DHS-approved data formats, and secure record retention for the required 7-year period.

Role-Based Access Control

Every user has a defined role (Admin, Coordinator, Caregiver, Billing). Access is limited to only the data necessary for that role. Admins can customize permissions at the agency level.

Multi-Factor Authentication

MFA is available for all accounts and required for Admin-level users. We support authenticator apps and SMS-based verification to protect against unauthorized access.

EVV GPS Security

Location data collected for Electronic Visit Verification is transmitted over encrypted channels, stored securely, and only accessible to authorized agency staff and state systems.

Audit Logs

Every action taken in the platform is logged — login events, record changes, exports, and billing submissions. Audit logs are tamper-resistant and retained per regulatory requirements.

Cloud Infrastructure

Infiniti Solution is hosted on enterprise-grade cloud infrastructure with high-availability architecture, automated failover, and automated daily backups.

Incident Response

We maintain a documented incident response plan. In the event of a data breach, affected clients are notified within 60 days as required by HIPAA, and remediation steps are taken immediately.

Security Testing

Our platform undergoes regular vulnerability assessments and penetration testing. We follow OWASP guidelines and remediate identified vulnerabilities on a priority basis.

Business Associate Agreement (BAA)

Every Infiniti Solution agency client receives a signed HIPAA Business Associate Agreement before processing any Protected Health Information. The BAA outlines our responsibilities, data handling procedures, and breach notification obligations.

To request a copy of our BAA or to discuss security requirements for your agency, contact us directly.

Responsible Disclosure

We take all security reports seriously. If you discover a vulnerability in our platform, please report it to us responsibly before public disclosure.

Security Team

Email: security@infinitisolution.org

We will acknowledge your report within 48 hours and provide a remediation timeline.

Questions about security?

Our team is happy to walk you through our security posture and answer any compliance questions.

Talk to Us →