Security
Access control, encryption, audit trails, and HIPAA-minded tools for spiritual care teams — summarized for leadership and IT reviewers.
Data protection at a glance
How Chaplain's Assistant layers security for spiritual care records — without exposing implementation secrets.
Protection stack
| Layer | Protects | What you get |
|---|---|---|
| In transit | Data moving between browsers and the service | Industry-standard TLS encryption on application traffic |
| At rest | Data stored in the cloud database and files | Cloud-provider encryption for stored records and objects |
| Application fields | Sensitive free-text spiritual care content | Optional field-level encryption for high-sensitivity text so plain names/notes are not left exposed in console views when enabled |
| Access & tenancy | Who can see which communities and records | Signed-in workforce accounts, roles, and company/community scoping so users only reach authorized sites |
| Platform boundary | Operator tools vs customer clinical data | Platform owner tools are designed to stay isolated from tenant clinical records |
| Integrity & audit | Trust in completed documentation | Attributable entries, policy-driven edit windows, and amendment reasons when clinical content is changed after the fact |
| Session & admin hygiene | Unattended workstations and privileged accounts | Idle session controls and multi-factor options for admins, configurable by organization policy |
| Shared responsibility | Overall program readiness | You control user provisioning, training, documentation policy, and any Business Associate Agreement with cloud providers required for your use case |
These controls support privacy-conscious, healthcare-adjacent spiritual care workflows. They are not a HIPAA certification claim. Organizations remain responsible for configuration, workforce access, training, and any agreements required for their regulatory posture.

Security commitment
Chaplain's Assistant is built for organizations that treat spiritual care documentation with the same rigor as clinical records. Security is a shared responsibility between MyMinistry.Help, your IT leadership, and day-to-day users.
Access control
The platform enforces role-based access at multiple levels:
- Firebase Authentication with email verification for workforce accounts
- Company and community scoping — users see only authorized communities
- Corporate admin, community admin, chaplain, and specialized roles (e.g., CPE)
- System owner tools isolated from tenant clinical data
Audit trails and documentation integrity
Visit logs, profile changes, and amendments are attributable and time-stamped according to your documentation policy. Original entries are preserved; governed edits require documented reasons when policy dictates. Empty draft sessions may be cancelled freely; content-bearing notes require an audit reason to cancel.
Anonymize mode
For trainings, screenshots, and shared screens, chaplains can toggle anonymize mode to mask resident names in the UI. See our Privacy Policy for limitations. We recommend using demo data for marketing captures.
Infrastructure
Application hosting and data storage use industry-standard cloud providers with encryption in transit (TLS) and at rest. Optional field-level encryption protects sensitive free text when enabled for your organization. API keys for optional AI features are server-side secrets — never exposed in client bundles.
Incident response
Report suspected security issues through your account manager or the contact form at /demo. We investigate validated reports promptly and coordinate with affected organizations.
Your responsibilities
Enforce strong passwords, revoke access promptly when staff depart, configure documentation policy before go-live, train chaplains on anonymize mode and amendment workflows, and complete any Business Associate Agreement with cloud providers required for your regulatory posture.
Related: Privacy Policy · Terms of Service · Contact / demo