SECURITY AND HIPAA
Security and HIPAA
Sella handles eligibility data that can include PHI. This notice describes our safeguards, BAAs, device permissions, and how to report an incident.
1. Purpose of this notice
This page is Sella’s public security and HIPAA notice. It is written for agencies considering Sella, for App Store and Google Play reviewers, and for workforce users who tap “HIPAA notice” in the app. It is not a substitute for a signed BAA or customer security questionnaire.
2. What Sella is — and is not
Sella is an eligibility tool for home health, home care, and hospice agencies. Authorized staff sign in, run coverage checks, and share a verdict with evidence. Sella is not a patient-facing consumer app, not a medical device, and not an electronic health record. It does not diagnose or treat.
Eligibility data can include PHI. We treat that data accordingly.
3. HIPAA and Business Associate Agreements
For covered-entity customers, Sella acts as a business associate. We will sign a BAA with your agency. Under that BAA we will:
- Use and disclose PHI only to provide the Service, as the BAA and HIPAA allow
- Apply administrative, technical, and physical safeguards
- Ensure workforce members are bound to confidentiality
- Require appropriate agreements with subcontractors that handle PHI
- Support customer rights and breach-notification duties as the BAA requires
Request a BAA from abe@sellahealth.com.
4. How we protect data
- Encryption in transit and at rest. Product traffic uses HTTPS. Data stored in the product environment is encrypted at rest.
- Authentication. Product users sign in with Microsoft Entra ID. Sessions use short-lived access tokens. Refresh material is stored in the device’s secure storage, not in ordinary app preferences.
- Tenant isolation. Customer data is scoped to the customer’s tenant. Users see the checks their organization is authorized to see.
- Least privilege. Internal access to production systems and PHI is limited to people who need it to operate the Service.
- Sanitized diagnostics. Error reports are built to exclude tokens, passwords, and raw eligibility payloads. Do not attach PHI to bug reports or screenshots.
5. Device permissions
The mobile apps may request:
- Camera and photos — only to capture an insurance card or face sheet. Text is recognized on the device to help fill the form.
- Face ID / biometrics — optional, on-device unlock. Sella does not collect biometric templates.
These permissions are not used for advertising or tracking.
6. Vendors
The product runs on Microsoft Azure. Sign-in uses Microsoft Entra ID. This website is hosted on Vercel and does not store PHI. Eligibility checks may be sent to CMS HETS and to commercial eligibility networks or clearinghouses required to complete the transaction. Apple and Google distribute the apps. Vendors that handle PHI do so under appropriate agreements. A current subprocessor list is available to customers on request.
7. Incidents
If we become aware of a security incident that affects your PHI, we will notify you as required by the BAA and applicable law. Report suspected incidents to abe@sellahealth.com immediately.
8. What we do not claim yet
SOC 2 Type II is on our 2026 roadmap. Until an independent report is available, we will share security details with design-partner agencies on request rather than publish a completed certification we do not have.
9. Related policies
Privacy Policy · Terms of Service
10. Contact
Security, HIPAA, or BAA questions: abe@sellahealth.com
Sella Health, Inc. · sellahealth.com
These pages describe how Sella works today. If something here does not match your contract or BAA, the signed agreement controls. Questions: abe@sellahealth.com.