Seriya Health · Security & Privacy
Your health data deserves
the same care you do.
Seriya Health is built on HIPAA-compliant infrastructure with signed Business Associate Agreements, end-to-end encryption, and strict access controls — so you can focus on healing.
Built With
HIPAA-Compliant Infrastructure
Encryption · BAAs · Zero PHI in Transit
“The Lord will keep you from all harm — he will watch over your life.”
Psalm 121:7 · The Standard We Hold Ourselves To
How We Protect You
Three layers of protection for every piece of your health data
From the moment you enter a check-in to when a caregiver receives an alert, your information is protected at every step.
Encryption at rest & in transit
All health data is encrypted with AES-256 at rest. Every connection uses TLS 1.2 or higher. Your data is unreadable to anyone without the decryption keys.
Row-level security
Every database table is locked so only you can access your own records. No other user’s data can ever be returned in response to your requests.
Secure device storage
Sensitive data on your phone lives in your device’s secure enclave — the same hardware that protects your Face ID and banking apps.
Generic notifications
Push notifications and SMS alerts never contain medication names or health data. They simply prompt you to open the app, where data is protected.
Signed Business Associate Agreements
Every vendor that touches your health data has signed a HIPAA Business Associate Agreement, making them legally accountable under federal law.
Your right to deletion
Delete your account and all associated health data at any time from within the app. Deletion is permanent and complete within 30 days.
Business Associate Agreements
Every vendor is legally accountable
A Business Associate Agreement (BAA) is a federal contract that makes our vendors legally responsible under HIPAA for protecting your health information. We only work with vendors who have signed one.
Amazon Web Services
Caregiver SMS alerts via SNS · BAA signed
Apple / Expo EAS
App distribution · No PHI transmitted
Our Commitments To You
What we never do with your health data
We never sell your data
Your health information is never sold, rented, or shared with advertisers, data brokers, or any third party for commercial purposes.
We never log PHI in system records
Our application logs contain zero health information. Medication names, check-in responses, and caregiver details never appear in any log file.
We never share data without consent
Your data is only shared with caregivers you explicitly invite. We never disclose your information to hospitals, insurers, or employers without your written authorization.
We never store PHI in notifications
Medication names and health details never appear in push notification banners or SMS messages — only inside the app, after you authenticate.
“Above all else, guard your heart, for everything you do flows from it.”
Proverbs 4:23
Seriya Health was built on the belief that healing is sacred — and that the information you share during your most vulnerable moments deserves the same reverence. Security isn’t a feature here. It’s a conviction.
Questions about your privacy?
We’re transparent about how your data is handled. Reach out anytime.