EMStool LLC — Cadence EMS

HIPAA Compliance Documentation

Security Officer: Jacob Russell Last Reviewed: July 2026 Classification: Internal / Partner Distribution
This page provides access to EMStool LLC's HIPAA Security Rule compliance documentation for Cadence, our cloud-based EMS patient care reporting and scheduling platform. These documents are available to authorized customers, partners, and auditors under NDA or BAA as applicable. For access requests, contact the Security Officer below.

Security Officer

Designated HIPAA Security & Privacy Officer
Jacob Russell, NR-EMT-P
Founder & Security Officer — EMStool LLC

Policy Documents

📋
Security & Privacy Officer Designation Complete
HIPAA-SEC-001  ·  45 CFR §164.308(a)(2)  ·  Effective June 2026
🔍
Risk Analysis & Management Complete
HIPAA-SEC-002  ·  45 CFR §164.308(a)(1)(ii)(A)  ·  14 threats assessed, 4 open items tracked  ·  June 2026
⚖️
Sanctions Policy Complete
HIPAA-SEC-003  ·  45 CFR §164.308(a)(1)(ii)(C)  ·  June 2026
🏢
Physical Security Policy Complete
HIPAA-SEC-004  ·  45 CFR §164.310  ·  June 2026
🎓
Workforce Training Policy Complete
HIPAA-SEC-005  ·  45 CFR §164.308(a)(5)  ·  June 2026
📖
Workforce HIPAA Training Curriculum Complete
Companion to HIPAA-SEC-005  ·  July 2026
🚨
Breach Notification Procedure Complete
HIPAA-SEC-006  ·  45 CFR §164.400–414  ·  June 2026
🤝
Vendor Documentation & BAA Summary Complete
HIPAA-SEC-007  ·  45 CFR §164.308(b)  ·  June 2026
📄
Patient Right of Access — Records Request Procedure Complete
HIPAA-SEC-008  ·  45 CFR §164.524  ·  July 2026
🗄️
PHI Retention & Deletion Policy Complete
HIPAA-SEC-009  ·  45 CFR §164.316(b)(2)  ·  July 2026
🔑
Workforce Access Offboarding Checklist Complete
HIPAA-SEC-010  ·  45 CFR §164.308(a)(3)(ii)(C)  ·  July 2026
Acceptable Use Policy Complete
HIPAA-SEC-011  ·  SOC2 CC1.1 / ISO 27001 5.10  ·  July 2026
🔗
Vendor Security Register Complete
HIPAA-SEC-012  ·  SOC2 CC9.1 / ISO 27001 5.23  ·  July 2026
📜
Information Security Policy Statement Complete
ISMS-2026-01  ·  SOC2/ISO 27001 5.1  ·  July 2026
🔍
Internal Audit Program Complete
IAP-2026-01  ·  SOC2/ISO 27001 5.36  ·  July 2026
🛡️
Secure Development Lifecycle Policy Complete
HIPAA-SEC-013  ·  SOC2/ISO 27001 8.25  ·  July 2026
🖥️
EMStool Internal Infrastructure Runbook Complete (internal only — not published)
HIPAA-SEC-014  ·  SOC2/ISO 27001 8.9  ·  July 2026
📦
Client Deployment Configuration Guide Complete
HIPAA-SEC-015  ·  July 2026
🗂️
PHI Field Inventory & Data Flow Complete
HIPAA-SEC-016  ·  SOC2/ISO 27001 C1.1  ·  July 2026

Supporting Documents

🔥
Incident Response Runbook
SOC 2 CC7.4  ·  Covers detection, containment, notification, and post-incident review  ·  June 2026
🔄
Change Management Policy
SOC 2 CC8.1  ·  Code review, deployment controls, rollback procedures  ·  June 2026
📊
Vendor Risk Register
SOC 2 CC9.2  ·  Third-party risk assessment for all sub-processors  ·  June 2026
♻️
Business Continuity & Disaster Recovery Plan
SOC 2 A1.3 / HIPAA 45 CFR §164.308(a)(7)  ·  RTO/RPO, backup verification, failover procedures  ·  June 2026
🔑
Encryption Key Rotation Procedure
SOC 2 CC6.7  ·  AES-256 key lifecycle, rotation schedule, emergency re-key  ·  June 2026
🏆
Certification Path Analysis (ISO 27001 vs. SOC 2 vs. HITRUST)
Internal  ·  Roadmap for formal third-party audit engagement  ·  June 2026

Technical Controls Summary

ControlRequirementStatus
Encryption at Rest45 CFR §164.312(a)(2)(iv)✅ AES-256 (InnoDB + file-level)
Encryption in Transit45 CFR §164.312(e)(2)(ii)✅ TLS 1.2/1.3 enforced, HSTS
Unique User IDs45 CFR §164.312(a)(2)(i)✅ Per-user accounts, no shared credentials
Automatic Session Timeout45 CFR §164.312(a)(2)(iii)✅ Configurable, minimum 15 minutes
Multi-Factor Authentication45 CFR §164.312(d)✅ TOTP + SMS OTP available
Audit Controls45 CFR §164.312(b)✅ Full audit log on all PHI access and writes
Role-Based Access Control45 CFR §164.308(a)(4)✅ 12-level role system, company-scoped
Encrypted Offsite Backup45 CFR §164.308(a)(7)(ii)(A)✅ GPG AES-256, Backblaze B2
Emergency Access45 CFR §164.312(a)(2)(ii)✅ Emergency role 99 with audit trail
Integrity Controls45 CFR §164.312(c)(1)✅ Chart lock prevents modification post-signature

Business Associate Agreement

EMStool LLC executes a Business Associate Agreement (BAA) with all covered entity customers prior to onboarding. To request a BAA or compliance documentation package, contact the Security Officer listed above.