Skip to the main content

Security and compliance

Written for practices that want to know what we hold, where it lives, and who can see it. The short answer: we hold no patient data, so there is very little to protect.

Last updated: September 4, 2026

HIPAA

Autism Friendly Care is not a HIPAA covered entity. We are not a provider, a health plan, or a clearinghouse. We are also not a business associate: we do nothing with patient information on a practice’s behalf.

There is no such thing as a HIPAA certification, and we do not claim one. We do not sign business associate agreements, because a listing never requires one.

Please do not send us patient records, appointment notes, or anything about a specific patient. Families who reach you through this site become your patients, not ours. Reply to them directly.

What we hold about families

An email address, a ZIP code if they share one, saved listings, and searches never tied to a name. We ask families not to include a patient’s name, diagnosis, or medications anywhere on the site.

A contact request holds the family’s name, email, insurance, and a short note. We email it to the practice and show it on the practice dashboard. Thirty days later we remove the name, email, insurance, and note. Only an anonymous record that a request was made stays behind.

Health-related data has its own policy page, as several state laws require.

What we hold about practices

Business information from public records, mainly the national NPI registry. Whatever the practice adds when it claims and updates a profile: accommodations, insurance, hours, photos. A work email for the person who claimed the listing.

Card details never reach us. Paid plans are billed by Stripe, and we store only the subscription status.

Where it lives

  • The site runs on Cloudflare Workers. The database is Cloudflare D1 and photos are in Cloudflare R2, all in Cloudflare’s data centers.
  • Every connection uses HTTPS. Data is encrypted at rest by Cloudflare.
  • Email is delivered by Resend. Payments are handled by Stripe.
  • There are no advertising trackers. Page views are counted with Cloudflare Web Analytics, which sets no cookies.

Who can see it

Sign-in is by emailed link. We store no passwords. The sign-in cookie is marked secure and cannot be read by scripts.

Staff tools sit behind Cloudflare Access, then a role check on every page, then a second check inside every action. Each staff action is written to an audit log with who did it and when.

A practice sees only its own dashboard. Nobody outside our small team sees another practice’s contact requests.

Abuse and breach handling

Public forms are rate-limited and carry spam traps. Ranking is payment-blind by construction, so there is no paid path to a higher position.

If a breach affects personal information, we notify the people affected as the law requires, including the FTC’s Health Breach Notification Rule where it applies.

Questions

Ask us anything about this page, or report a security concern, at privacy@autismfriendlycare.com. We answer within 30 days, and security reports much sooner.