Resident identities are never stored
When a partner agency enters a resident into the system, the person's name and date of birth are immediately converted into a one-way hash using a secret server-side key. We cannot reverse the hash, and we do not store names or dates of birth at all. We do not collect Social Security numbers. What is stored alongside the hash is limited coordination detail such as initials, birth year, and the first part of a ZIP code. Two agencies can recognize that they are helping the same person only by comparing these hashes within the network, and only when consent allows that sharing.
Consent is required before any sharing
Sharing depends on a consent record that agency staff record with the resident. If no consent record exists, or it has expired, the system defaults to the least sharing possible — usually no access at all. Consent can be limited by data type, exclude specific organizations, carry an expiration date, or be withdrawn at any time, and every change is recorded in an audit trail showing who made it, when, and what changed. Agencies are notified before a consent they rely on expires.
Role-based access and least privilege
Partner agency staff only see the data they need for their work. Network administrators can manage directory entries and agency approvals, but they do not access case notes or referral details between agencies. Organization admins can invite and manage their own team members. Row-level security policies in the database enforce these rules at the data layer, not just in the application interface.
Encrypted connections and infrastructure
Traffic between your browser and our servers uses HTTPS/TLS. Passwords are handled by our managed authentication provider and are never stored by us in readable form. The database is hosted by a managed cloud provider that encrypts data at rest and takes automated backups. We do not sell, rent, or share resident or agency data with advertisers or data brokers, and the site uses no advertising or analytics trackers. We rely on a small number of service providers to operate the network; they are listed in our Privacy Policy.
Audit trails and accountability
The system keeps timestamped records of major actions: referral creation, status changes, assignments, consent updates, and profile edits. Agency staff can view the history for referrals and consent records they are authorized to see. This supports quality improvement and makes it easier to understand what happened if a case needs review.
Responsible disclosure
If you believe you have found a security or privacy issue in Kalamazoo Care Network, please report it to us privately. We will investigate promptly and keep your report confidential while we assess it.