LEGAL

Privacy Policy

Privacy Policy

Effective September 1, 2026 · Version 1.0 · HIPAA Business Associate

Effective September 1, 2026 · Version 1.0 · HIPAA Business Associate

HIPAA Notice: WeCareE operates as a Business Associate under HIPAA. We execute a signed Business Associate Agreement (BAA) with every healthcare facility before any Protected Health Information is processed through our Service. To request a BAA, email privacy@wecaree.ai.


1. Scope and Applicability

WeCareE ("WeCareE," "we," "us," or "our") is a product of Appex Innovation Solutions LLC, a Delaware limited liability company with its principal place of business at 103 Carnegie Center Drive, Princeton, New Jersey 08540, United States.

WeCareE is an AI-powered mobile nursing documentation platform for licensed healthcare professionals in skilled nursing facilities (SNFs), home care agencies, and post-acute care settings in the United States.

This Privacy Policy applies to all users of the WeCareE mobile application (iOS and Android), web application, and related services (collectively, the "Service"), including:

  • Nurses and clinical staff using the WeCareE mobile app

  • Directors of Nursing, facility administrators, and supervisors using the web dashboard

  • Family members accessing the Family Portal with facility-granted permissions

  • Facility administrators managing accounts through the Admin Web interface

By downloading, installing, or using WeCareE, you agree to this Privacy Policy.


2. Who We Are: HIPAA and Business Associate

WeCareE operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations (45 C.F.R. Parts 160 and 164). We execute a Business Associate Agreement (BAA) with each healthcare facility (Covered Entity) before any Protected Health Information (PHI) is processed through our Service.

If you are a facility administrator, a signed BAA with Appex Innovation Solutions LLC must be in place before onboarding nurses or patients. To request a BAA, or for questions about our HIPAA compliance posture, contact us at privacy@wecaree.ai.


3. Information We Collect

3.1 Account and Identity Information

When a facility administrator creates accounts, we collect:

  • Full name and professional license number (RN, LPN, CNA, or equivalent)

  • Email address, phone number, and role or job title

  • Facility name and address

  • Profile photo (optional)

3.2 Protected Health Information (PHI)

WeCareE is a clinical documentation platform. In the course of using the Service, nurses create and store records that may constitute PHI under HIPAA, including:

  • Patient name, date of birth, gender, and medical record number (MRN)

  • Admission date, diagnosis, and care plan information

  • Clinical assessments: vital signs, wound assessments, Morse Fall Scale scores, Braden Scale pressure ulcer risk scores, NPUAP bedsore staging (Stage I–IV), bathing records, repositioning logs, infection control records, medication administration records

  • Clinical notes, shift nursing assessments, and change-in-condition documentation

  • Clinical photographs of wounds, skin conditions, and other findings

  • Escalation alerts and SOS notifications generated by the system

  • Family portal data shared with authorized family members

All PHI is collected on behalf of and at the direction of the healthcare facility (Covered Entity). PHI is not used by WeCareE for any purpose other than providing the contracted Service.

3.3 Device and Technical Information

We automatically collect device type and OS version, app version, IP address, unique device identifier, crash logs, performance data, session timestamps, and data synchronization logs.

3.4 Location Data

WeCareE may collect approximate location data for Electronic Visit Verification (EVV) compliance for home care nurses and geofencing to verify care was delivered at the correct patient location. Location data is used solely for EVV compliance and is never used for advertising or sold to third parties.

3.5 Camera and Photo Access

WeCareE requests camera access to capture clinical photographs such as wound images, skin conditions, and bedsore documentation. All photos taken within WeCareE are stored exclusively in encrypted Google Cloud Storage (GCS) in the United States and are accessible only to the facility's authorized care team.

3.6 Push Notifications and DND Override

WeCareE uses Firebase Cloud Messaging (FCM) for push notifications. Critical clinical alerts, including Stage III/IV bedsore detection, deteriorating wound status, critical vital signs, and nurse SOS alerts, use Do-Not-Disturb (DND) override to ensure immediate delivery for patient safety. By using WeCareE, you acknowledge that the app may override your device's Do-Not-Disturb settings for these critical clinical alerts.


4. How We Use Your Information

4.1 To Provide the Service

We use information collected to authenticate users securely, display assigned patients and scheduled care tasks, record and store clinical documentation, generate real-time alerts to DONs and supervisors, support offline documentation and synchronization, and provide the DON dashboard, floor lead view, family portal, and admin web functionality.

4.2 Clinical Safety and Escalation

WeCareE uses clinical data to generate automated patient safety alerts including escalation for Stage III/IV pressure ulcers, wound deterioration, critical vital signs, repositioning compliance monitoring, and nurse SOS alerts. These may include DND-override push notifications.

4.3 FHIR R4 Interoperability

WeCareE writes clinical records to GCP Cloud Healthcare API in HL7 FHIR R4 format, enabling integration with the EHR systems used by skilled nursing facilities, CMS-compliant audit trail generation, and data portability for facility use.

4.4 AI and Analytics

WeCareE uses aggregated, de-identified clinical data to improve documentation accuracy, develop predictive models for pressure ulcer risk, fall prediction, and readmission risk, and generate facility-level compliance analytics. We do not use identifiable PHI to train AI models.

4.5 Legal Compliance

We may use or disclose information as required to comply with applicable law, respond to lawful government requests, fulfil our HIPAA Business Associate obligations, and comply with CMS documentation requirements applicable to SNFs.


5. How We Share Your Information

5.1 With Your Healthcare Facility

All clinical data you create in WeCareE belongs to your employing facility. The facility has full access to clinical records, audit logs, nurse documentation, and compliance data through the DON dashboard and admin web interface.

5.2 With Authorized Care Team Members

Nurses, DONs, floor leads, physicians, and other authorized care team members may access patient records in accordance with their role-based permissions within WeCareE.

5.3 With Authorized Family Members

Where a facility grants Family Portal access, limited non-clinical information is visible to family members, including task completion status, vital signs, and nurse notes marked as family-visible. Clinical wound photographs and medication details are not accessible to family members.

5.4 Technology Subprocessors

WeCareE uses the following key subprocessors, all bound by data protection obligations:

  • Google Cloud Platform (GCP): cloud hosting, Firestore database and Cloud Storage. Data location: United States.

  • GCP Cloud Healthcare API: FHIR R4 clinical data store. Data location: United States.

  • Google Firebase / FCM: push notification delivery. Data location: United States.

We do not sell or share PHI with any third party for advertising, marketing, or commercial purposes.

5.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, data may be transferred to the acquiring entity subject to the same protections described in this policy and applicable HIPAA requirements.

5.6 Legal Requirements

We may disclose information when required by law, regulation, subpoena, or court order, or when necessary to protect the rights, property, or safety of WeCareE, our users, or the public.


6. Data Storage and Security

6.1 Where Your Data Is Stored

All WeCareE data is stored exclusively in Google Cloud Platform infrastructure in the United States (us-central1 and us-east1 regions). No PHI is stored outside the United States.

6.2 Security Measures

  • Encryption in transit: all data transmitted using TLS 1.2 or higher

  • Encryption at rest: AES-256 encryption for all data in Firestore, GCS, and GCP Cloud Healthcare API

  • Authentication: SMART on FHIR (OAuth 2.0) with multi-factor authentication support

  • Role-based access control: least-privilege access; nurses see only their assigned patients

  • Audit logging: every PHI read, write, and access event logged with timestamp, user ID, and action in an immutable audit log

  • Offline data protection: locally cached data is encrypted and requires device authentication to access

  • Security assessments: annual third-party penetration testing

6.3 HIPAA Security Rule Compliance

WeCareE is designed and operated in accordance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C), including Administrative Safeguards, Physical Safeguards, and Technical Safeguards.

6.4 Breach Notification

In the event of a security breach affecting PHI, WeCareE will notify affected Covered Entities in accordance with the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D) within the required timeframes.


7. Data Retention

WeCareE retains clinical documentation and PHI for the duration of the facility's active subscription and for a minimum period thereafter as required by applicable law and CMS regulations. Specific retention periods are defined in the Business Associate Agreement with each facility.

Upon termination of a facility subscription, clinical data is retained for 90 days during which the facility may request an export. After 90 days, data is permanently deleted from all WeCareE systems unless otherwise required by law.

Individual nurse accounts deactivated by facility administrators preserve historical documentation records, which remain accessible to the facility.


8. Your Rights

8.1 Rights of Nurses and Staff

As a WeCareE user, you have the right to access a copy of the personal account information WeCareE holds about you, request correction of inaccurate personal information, and request deactivation of your personal account by contacting your facility administrator or WeCareE support.

Clinical documentation records you created as part of your nursing duties are owned by and under the control of your employing facility, not by you individually. Requests regarding patient PHI should be directed to your facility's Privacy Officer.

8.2 Rights of Patients

Patients whose information is documented in WeCareE have rights under HIPAA exercised through their healthcare facility (the Covered Entity). Patients should contact their facility's Privacy Officer to exercise HIPAA rights including the right to access, amend, or request an accounting of disclosures of their PHI.

8.3 California Residents (CCPA)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). WeCareE does not sell personal information. For CCPA inquiries, contact us at privacy@wecaree.ai.


9. Children's Privacy

WeCareE is a professional healthcare application intended solely for use by licensed healthcare professionals and facility administrators aged 18 and over. WeCareE does not knowingly collect personal information from individuals under the age of 18. If you believe a minor has used the Service, please contact us immediately at privacy@wecaree.ai.


10. Offline Functionality

WeCareE supports offline documentation. When your device has no internet connection, clinical data is stored locally in encrypted form and automatically syncs to WeCareE servers when connectivity is restored. Offline data is protected by device-level authentication. You are responsible for maintaining the physical security of your device when it contains locally cached clinical data.


11. Camera, Notifications, and Device Permissions

  • Camera: capture clinical wound photos and skin assessment images. Required for photo-enabled modules.

  • Push notifications: clinical alerts and task reminders, including DND override for critical patient safety alerts. Required.

  • Location: Electronic Visit Verification (EVV) for home care nurses. Home care users only.

  • Local storage: store clinical data for offline documentation. Required.

You may manage permissions in your device settings. Revoking required permissions may limit functionality of the Service.


12. Third-Party Links

The WeCareE application may contain links to external websites or resources. WeCareE is not responsible for the privacy practices or content of those third-party sites. We encourage you to review their privacy policies before sharing any personal information.


13. Cookies (Web Application)

The WeCareE web application (DON dashboard and admin web) uses essential cookies to maintain authentication sessions. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies that transmit identifiable data.

Our public marketing website (wecaree.ai) uses Google Analytics to understand aggregate visitor traffic, such as pages visited and referring sites. The website does not collect PHI. You can block these cookies in your browser settings.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this policy, post a notice within the WeCareE application, and notify facility administrators by email at least 14 days before changes take effect. Your continued use of WeCareE after the effective date constitutes acceptance of the updated policy.


15. Contact Us

Privacy Officer, WeCareE

Appex Innovation Solutions LLC, 103 Carnegie Center Drive, Princeton, New Jersey 08540, United States

Privacy: privacy@wecaree.ai · Support: support@wecaree.ai · Phone: +1 609-917-3344

For HIPAA inquiries or BAA requests, email privacy@wecaree.ai with the subject "HIPAA – [Nature of Inquiry]".

A MyHealth product by Appex Innovation Solutions LLC · Princeton, NJ


Get in Touch

Want to test WeCareE at your facility? Let's talk about a free 45-day pilot.

Request Free Pilot

© 2026 Appex Innovation Solutions LLC. All rights reserved. WeCareE is a product of Appex Innovation Solutions LLC.

© 2026 Appex Innovation Solutions LLC. All rights reserved. WeCareE is a product of Appex Innovation Solutions LLC.