Care-Call.AI
← Home

HIPAA Notice of Privacy Practices

Effective date: April 2026 · Last updated: April 2026

This notice describes how medical information about residents may be used and disclosed and how residents can get access to this information. Please review it carefully.

1. Our role as a Business Associate

Care-Call.AI is operated by NIUSIA CO.,LTD. When a Covered Entity — such as an Assisted Living facility, skilled nursing facility, or home-care agency regulated by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") — enrolls residents on Care-Call.AI, NIUSIA acts as a HIPAA Business Associate as defined in 45 CFR §160.103.

Before ingesting any Protected Health Information ("PHI") we execute a Business Associate Agreement ("BAA") with the facility. That BAA, together with this Notice, the Privacy Policy, and the Terms of Service, governs how we handle PHI.

2. What counts as PHI at Care-Call.AI

  • Resident name, age, room number, phone number and language.
  • Voice recordings of AI wellness calls.
  • Transcripts and AI-generated summaries of those calls.
  • Sentiment scores, anomaly flags, and trend reports.
  • Any consent documents uploaded through the dashboard.
  • IP addresses and timestamps associated with the above.

3. Permitted uses and disclosures

We use and disclose PHI only for the following purposes:

  • Treatment support: providing transcripts, summaries and alerts to authorised facility staff.
  • Payment: calculating invoices based on active residents (we do not transmit PHI to Stripe; only resident counts are shared for billing).
  • Health-care operations: quality monitoring, fraud detection, and improvement of our voice and summary models, in each case using de-identified data only.
  • As required by law: responding to subpoenas, court orders, public-health authorities, and reports of suspected elder abuse.
  • As permitted by our BAA: with your facility and its authorised designees.

Any other use of PHI — for example, marketing, research, or sale — requires explicit written authorisation from the resident or their legal representative.

4. AI processing of PHI

Care-Call.AI relies on large language models and realtime voice models from OpenAI, L.L.C. and Anthropic, PBC to deliver the Service. All PHI is sent to these sub-processors over TLS 1.2+ under zero-retention contractual terms, meaning the providers do not retain or train on PHI. NIUSIA maintains signed BAAs or DPAs equivalent to a BAA with every sub-processor that can touch PHI.

5. Resident rights under HIPAA

Each resident has the right to:

  • Access their PHI — receive a copy of any call transcript, summary or record we hold (45 CFR §164.524).
  • Request amendment of any PHI they believe is inaccurate (§164.526).
  • Request an accounting of disclosures for the 6 years preceding the request (§164.528).
  • Request restrictions on certain uses or disclosures (§164.522).
  • Request confidential communications — for example, asking us to use a specific phone number or email.
  • Receive a paper copy of this Notice on request, even if they received it electronically.
  • File a complaint with their facility, with NIUSIA via the contact form on our website (choose the Privacy category), or with the US Department of Health and Human Services Office for Civil Rights. No retaliation will result from filing a complaint.

Rights requests should be submitted through the facility administrator, who will verify identity and forward the request to NIUSIA. We respond within 30 days, with one 30-day extension permitted.

6. Safeguards

  • TLS 1.2+ encryption in transit; AES-256 encryption at rest.
  • Role-based access with least-privilege defaults and mandatory 2FA for NIUSIA staff.
  • Immutable audit logs retained for 6 years.
  • Annual third-party penetration tests and quarterly vulnerability scans.
  • Formal risk analysis, contingency plan and documented incident response procedure.
  • Workforce training on HIPAA Privacy and Security Rules.

7. Breach notification

In the event of an unauthorised acquisition, access, use, or disclosure of unsecured PHI, we will notify the affected Covered Entity without unreasonable delay and in no case later than 60 days after discovery, in accordance with 45 CFR §164.410. The notification will include a description of the incident, the types of PHI involved, mitigation steps taken and our recommendations for the Covered Entity's own notification obligations.

8. Retention and destruction

PHI is retained according to the schedule in the Privacy Policy §6 and is cryptographically erased at end-of-life. On termination of the BAA we will, at the Covered Entity's direction, either return or destroy all PHI in our possession and provide written certification of destruction.

9. Changes to this Notice

We reserve the right to change this Notice and to make the new Notice effective for all PHI we maintain. Material changes will be posted to this page and emailed to facility administrators at least 14 days before the effective date.

10. Contact

NIUSIA CO.,LTD. HIPAA Privacy Officer
Contact: use the contact form on our website and select the Privacy category.
Office: NIUSIA CO.,LTD., Tokyo, Japan

You may also file a complaint with the US Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue SW, Room 509F HHH Bldg., Washington DC 20201, or online at hhs.gov/hipaa/filing-a-complaint.

HIPAA Notice of Privacy Practices · Care-Call.AI