KR App is built to meet HIPAA technical safeguard requirements and California state health-data privacy law. This page explains what our platform does, what data we handle, and how we protect the individuals we serve.
KR App is a clinical workflow platform operated by Kindful Restoration Inc. to support care coordination for Medi-Cal members enrolled in CalAIM programs including Enhanced Care Management (ECM) and Community Supports. The platform is used exclusively by authorized Kindful Restoration staff. Members do not log in directly; staff access records on members’ behalf during care planning, enrollment, and service delivery.
AI-assisted creation and management of housing support plans required for Medi-Cal ECM and CalAIM. Captures member needs, goals, and service coordination details.
PHI: Name, DOB, Medi-Cal ID, ICD-10 codes, housing needsCommunity Health Worker plans of care documenting interventions, goals, and progress for members enrolled in CHW services under Medi-Cal.
PHI: Name, DOB, Medi-Cal ID, clinical notes, diagnosesCase management records for high-complexity Medi-Cal members. Tracks contact history, care team assignments, and care coordination notes.
PHI: Name, DOB, Medi-Cal ID, care notes, contact historyTwo-step digital enrollment collecting demographic and insurance information and creating the member record in the internal CRM.
PHI: Name, DOB, address, Medi-Cal ID, insurance, phoneHIPAA-aware SMS and voice communication with members via Twilio. All messages are logged and linked to member records. Staff-only access.
PHI: Phone numbers, message content, call recordsDigital form completion and e-signature collection for 14 clinical document types. Generates signed PDF output with QR-code audit trail.
PHI: Signatures, clinical form data, member identityInternal member management replacing third-party CRM tools. All member data stays within Kindful Restoration’s infrastructure.
PHI: Name, DOB, address, Medi-Cal ID, contact detailsThe Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations at 45 CFR Parts 160 and 164 require covered entities and their business associates to implement administrative, physical, and technical safeguards to protect Protected Health Information (PHI). The following describes how KR App implements the HIPAA Security Rule Technical Safeguards.
Cache-Control: no-store, preventing PHI from being stored in browser
caches or intermediate proxies.
Every response from the platform includes the following HTTP security headers:
X-Frame-Options: DENY — prevents clickjacking via iframe embeddingX-Content-Type-Options: nosniff — prevents MIME-type sniffing attacksReferrer-Policy: no-referrer — prevents URL leakage across navigationPermissions-Policy — disables geolocation, microphone, and camera browser APIsStrict-Transport-Security — enforces HTTPS for one year in productionCache-Control: no-store — prevents PHI caching on all responsesKR App processes the following categories of PHI in connection with Medi-Cal care coordination:
PHI is used solely for treatment, care coordination, and healthcare operations on behalf of Kindful Restoration’s Medi-Cal program participants. We apply the HIPAA minimum necessary standard: staff members access only the PHI required for their specific role and the specific task at hand.
The IHSP and CHW modules use a large language model (OpenAI GPT-4o) to assist clinical staff in drafting care plan narratives. Member PHI submitted to the AI model is used solely to generate the requested clinical content. A Business Associate Agreement (BAA) governing this processing is maintained with OpenAI, and OpenAI does not use submitted data to train its public models. All AI-generated content is reviewed and approved by a clinical staff member before being saved or acted upon.
Member records and associated clinical documents are retained for a minimum of seven (7) years from the date of creation, consistent with California Health & Safety Code requirements and HIPAA standards. Audit log records are retained for the same period. Records are securely deleted after the applicable retention period expires using methods that render the data unrecoverable.
Kindful Restoration does not sell, rent, share, or monetize member PHI in any form. PHI is never used for advertising, data brokerage, or any purpose unrelated to the direct care and operational support of the individuals to whom it belongs.
In addition to HIPAA, Kindful Restoration complies with the California Confidentiality of Medical Information Act (Cal. Civ. Code §§ 56–56.37). The CMIA provides additional protections for California residents, including heightened confidentiality requirements for mental health, substance use disorder, reproductive health, and certain other categories of sensitive health information that go beyond HIPAA’s baseline protections.
To the extent the CCPA applies to our operations, Kindful Restoration honors its requirements. Information collected and maintained in connection with HIPAA-covered healthcare operations is generally exempt from CCPA under the medical information exemption (Cal. Civ. Code § 1798.145(c)). Individuals who believe they have CCPA rights not covered by the HIPAA exemption may contact our Privacy Officer.
In the event of a breach involving California residents’ personal or medical information, Kindful Restoration will provide notification as required by the California data breach notification statute (Cal. Civ. Code § 1798.82) and the CMIA (§ 56.36), in addition to the federal HIPAA Breach Notification Rule requirements.
As a provider participating in California’s CalAIM initiative, Kindful Restoration adheres to the data-sharing and care coordination requirements established by the California Department of Health Care Services (DHCS) for Enhanced Care Management (ECM) and Community Supports programs. These requirements govern how member data is shared with managed care plans and other authorized parties in the member’s care team.
Under HIPAA, vendors that access, process, or transmit PHI on behalf of a covered entity must execute a Business Associate Agreement (BAA). The following third-party services are used by KR App in connection with PHI:
All Business Associate Agreements are reviewed and renewed at least annually. If a BAA cannot be executed or maintained with a vendor that processes PHI, that vendor’s service is discontinued for any use involving member health information.
As a HIPAA-covered entity, Kindful Restoration recognizes and upholds the following individual rights regarding Protected Health Information:
You have the right to inspect and obtain a copy of your PHI held by Kindful Restoration, including records created and maintained in KR App. Requests must be submitted in writing to the Privacy Officer. We will respond within 30 days (or 60 days with notice of extension if additional time is needed).
You have the right to request amendment of your PHI if you believe it is inaccurate or incomplete. Kindful Restoration may deny a request if the information is already accurate and complete, or was not created by this organization.
You have the right to receive an accounting of disclosures of your PHI made by Kindful Restoration, except for disclosures made for treatment, payment, or healthcare operations. Requests cover disclosures made within the past six years.
You have the right to request restrictions on certain uses and disclosures of your PHI. Kindful Restoration is not required to agree to all restriction requests, except where you have paid out-of-pocket in full for a specific service and request that information not be disclosed to your health plan.
You have the right to request that we communicate with you about health matters in a specific way or at a specific location (for example, contacting you only at a particular phone number). We will accommodate all reasonable requests.
To exercise any of the rights above, contact the Privacy Officer in writing using the contact information in the section below. All requests are acknowledged within five (5) business days.
KR App is designed and operated with reference to the following frameworks and regulations:
For compliance inquiries, privacy rights requests, or to report a suspected privacy violation, contact Kindful Restoration’s designated Privacy Officer:
Mailing address:
Kindful Restoration Inc.
7344 Magnolia Ave., Suite 110
Riverside, CA 92504
Phone: (951) 404-0856
If you believe your privacy rights have been violated, you also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr/privacy or by calling 1-800-368-1019. Filing a complaint will not result in any retaliation by Kindful Restoration.