Security at NextCaregiver
Last updated September 5, 2026
An overview of NextCaregiver security and privacy safeguards for family care information.
Access controls
Each care record is permission-based. Owners and invited family members receive access according to their role, and the application checks those permissions when records are read or changed.
Authentication
Accounts require authentication and email verification. Users should choose a unique password, protect their email account with multifactor authentication, and sign out of shared devices.
Private files and notifications
Documents use private uploads and protected access links. Family notification emails contain a generic notice and intentionally omit care details.
Human review
AfterCall Update creates an editable draft. It cannot silently change the medication list; every proposed medication change requires explicit human confirmation, and the original note remains available.
Payments
Web payment details will be collected using Stripe-hosted Checkout, so NextCaregiver does not store card numbers. Payment secrets and webhook signing secrets must remain server-side. Native app subscriptions will use Apple or Google billing.
Scope and reporting
NextCaregiver does not currently claim HIPAA compliance or a healthcare-provider business associate agreement. Avoid entering data your organization is legally prohibited from storing here. Report a suspected security issue to roquerodriguez27@gmail.com without including care details.
