Built HIPAA-scoped from the first commit.
Judi is an orchestration layer over the agency's clinical system, not a replacement for it. This page says exactly what that means, including what is not finished yet.
AlayaCare stays the system of record
Clinical and scheduling data live in AlayaCare. Judi reads what one screen needs to render and holds nothing clinical beyond that. When a nurse asks to swap, decline or run late, the request goes to the Scheduling group and the change is keyed in AlayaCare. Judi never edits a schedule, a chart or an order.
What Judi stores, and what it never does
Judi holds
- User accounts and roles
- Nurse profiles: licence state, home ZIP for distance sorting, push token
- Messages and IV-site photos, encrypted
- Referral records and the referral CRM
- Education module list and who completed what
- The audit log
Judi never holds
- The clinical chart, orders, or care plans
- A second copy of the schedule
- Patient addresses sent to any third-party API
- Photos on the camera roll or in iCloud
- Patient information in a push notification
- Plaintext patient information in logs, crash reports or analytics
Encryption
Everything is encrypted in transit and at rest. IV-site photos are taken inside the app, encrypted before they are written, attached to the visit, and never offered to the camera roll or to iCloud backup. There is no library picker. Nothing is kept in plaintext on the phone.
An audit log on every read
Every time a photo or a message is opened, the server writes who, what and when. The log is written server-side, so a client cannot skip it. Role-based access is also enforced server-side; the app never decides on its own what a role may see.
No patient information in a push
A notification carries a title and an ID. The app fetches the content after the person signs in, over the same authenticated connection as everything else. A locked phone on a kitchen counter shows nothing a visitor could read.
Access ends the same day
When an admin deactivates a nurse, messaging, photos and education on that phone are cut immediately. Deactivation propagates in real time rather than at the next sign-in.
The message archive is exportable by one role
Exactly one role at the agency can export the message archive. Nurses and schedulers cannot. That is a deliberate narrowing, not a missing feature.
Addresses never leave the server
Distance sorting uses ZIP centroids, so no patient address is sent to a mapping API. Directions open Google Maps on the nurse's own device, from the device, once the visit is theirs.
Hosting, and what is not finished yet
Production hosting is AWS, using only services covered by a Business Associate Agreement, with the agency as the covered entity. That is the design and the commitment.
Candidly: the demo you can reach today at app.meetjudi.com runs on Vercel, which is not BAA-eligible, with seeded dummy data and no real patients. It moves to AWS before any agency puts real information in it. If you are evaluating Judi for your agency, ask us where that migration stands.
Questions
Compliance questions go to privacy@meetjudi.com. For a walkthrough with your compliance officer in the room, ask for a demo.