HIPAA-ready, for agencies
Last updated October 4, 2026
EMS Run Sheet is designed to support HIPAA compliance, with all data stored encrypted on-device. It has no server and no accounts: patient information is created, kept and destroyed on the iPhone or iPad it was entered on. We, the developer, never receive, store or process it.
What that means for your agency: because we never have access to your patients' information, we aren't a business associate and no Business Associate Agreement (BAA) is needed to use Run Sheet. HIPAA compliance itself belongs to your agency (your risk analysis, policies, training and device management). Run Sheet provides the technical safeguards those depend on; no app can make an agency "HIPAA compliant" on its own, and there's no official HIPAA certification for software.
The technical safeguards (45 CFR 164.312)
| Safeguard | How Run Sheet provides it |
|---|---|
| Access control: unique user identification | On shared agency devices, each crew member signs in before seeing patient information; every privacy log entry names them. On a personal device, the user is the device owner. |
| Access control: device passcode | Patient information can't be opened on a device without a passcode. Photos and scans can't be shared or saved to Photos; they stay inside the app until they're erased. |
| Access control: emergency access | Patient information unlocks with Face ID, Touch ID or the device passcode, so it's never locked out when needed. |
| Access control: automatic logoff | Patient information locks when the app is left and after 2–30 minutes without use (agency-settable). |
| Access control: encryption and decryption | AES-256-GCM for every call, patient, note, photo and scan. The key is generated on the device and stored in its Keychain as "this device only": never synced, never backed up, never sent. Data is also protected by iOS Data Protection. |
| Audit controls | An encrypted, on-device privacy log of sign-ins, unlocks, automatic locks, copies, shares, deletions, retention erasures and setting changes. Exportable as CSV for your records. It never contains patient information itself. |
| Integrity | AES-GCM is authenticated encryption: any change to stored data is detected and the data is rejected. |
| Person or entity authentication | Face ID, Touch ID or the device passcode before patient information is shown, plus crew sign-in on shared devices. |
| Transmission security | Nothing is transmitted to us. Speech recognition and document scanning run on the device; Run Sheet won't send patient speech to a server. Copied text stays on the device (no Universal Clipboard) and expires in 5 minutes. Sharing a call between crew uses AirDrop or Messages, encrypted by Apple in transit, and agencies can turn patient sharing off. |
Retention and destruction
- Patient details (names, scans, photos, notes, MRNs) are erased automatically 12 hours to 90 days after each call ends: 7 days by default, 12 hours on shared devices. Times, address and hospital stay for your records unless you also delete whole calls.
- Whole calls can be deleted automatically after 30 days, 90 days or a year.
- Erase All Data destroys the encryption key first, making every call, patient and photo unreadable at once, then deletes them. Use it before reassigning or retiring a device.
- Patient data is excluded from iCloud and computer backups, so it can't be restored onto another device.
Shared truck iPhones and iPads
Set a device as a Shared agency device (Settings → This device, or by MDM). Crew sign in to see patients, patient details erase after 12 hours by default, patient information locks when each call ends, and personal shift tracking is off. On iPad, Run Sheet runs beside your ePCR in Split View, so details drag or copy straight across.
Deploying with your MDM
Run Sheet reads Apple's Managed App Configuration. Any value your MDM sets is enforced and can't be changed on the device.
| Key | Type | What it does |
|---|---|---|
sharedDevice | Boolean | Shared agency device mode |
patientRetentionHours | Integer | Erase patient details this many hours after a call (0 = keep) |
callRetentionDays | Integer | Delete whole calls this many days after they end (0 = keep) |
autoLockMinutes | Integer | Lock patient information after this many minutes without use |
allowPatientSharing | Boolean | Allow sending patient details by AirDrop or Messages |
hidePatientsWhenRecording | Boolean | Hide patients during screen recording or mirroring |
requireCrewSignIn | Boolean | Crew sign-in on shared devices |
lockScreenPatientLine | Boolean | Show the patient's age and sex on the Lock Screen and Apple Watch |
agencySetupLink | String | Your agency's setup link (from Settings → Agency → Share → QR code), installed automatically |
Pair it with your MDM's own device policies: a required passcode, automatic screen lock, and remote wipe for lost devices.
What stays with your agency
- Your HIPAA risk analysis, policies, workforce training and sanctions.
- Device management: passcodes, OS updates, lost-device procedures.
- What crews do with information after it leaves Run Sheet, for example what's pasted into your ePCR or sent in Messages.
- Business Associate Agreements with vendors who do hold your data, such as your ePCR provider.
Good to know
- Address searches and drive times use Apple Maps, which receives the address or location looked up, but no patient information.
- The agency directory is a public, signed file the app downloads; it sends nothing about you or your patients.
- Run Sheet is a documentation aid, not a medical device and not an ePCR. Your official patient care report stays in your ePCR.
Questions
For deployment help or a security questionnaire: support@emsrunsheet.com