Healthcare background screening, with a BAA.
Screen caregivers, clinicians and contractors against criminal records across more than a thousand county, state and federal jurisdictions and 58 US sex offender registries — one API call, on an account we will sign a Business Associate Agreement for. Built for regulated buyers: healthcare and home care, staffing, and screening providers.
Prefer email? support@offendersearch.app reaches the same team.
We will sign a BAA with eligible enterprise customers
If you handle protected health information (PHI) and process it through the Offendersearch API — for example, screening patients, caregivers, or home-care staff — we will enter into a Business Associate Agreement that governs how we handle that data on your behalf. The BAA sets out permitted uses, safeguards, breach-notification obligations, and each party’s responsibilities.
- Available to eligible enterprise accounts that process PHI through the API.
- Scoped to your use case during procurement — no boilerplate you can’t map to.
- HIPAA compliance is a shared responsibility; the BAA defines each side’s obligations.
- Backed by the security controls documented below, not just paperwork.
Our security posture
An honest view of the controls in place today and where we’re investing. We describe our posture and roadmap — we don’t claim certifications we don’t hold.
Encryption in transit & at rest
All API traffic is served over TLS. Data stored by the platform — including customer records and generated reports — is encrypted at rest using industry-standard AES-256.
Least-privilege access controls
Internal access to production data is role-scoped and granted on a need-to-know basis. Administrative actions are gated behind authentication and reviewed periodically.
Per-account API keys, hashed at rest
Each account gets its own API keys. Secrets are stored as one-way hashes — we never keep the raw key — so a database read can never expose a usable credential. Keys can be rotated or revoked at any time.
Audit logging
API requests are logged with account, timestamp, and endpoint so activity can be reviewed and reconciled. Usage is visible to account owners in the dashboard.
Data retention & freshness controls
The sex-offender data carries lastCheckedAt on every record, with optional live re-verification per request, and customer-submitted identifiers are retained only as long as needed to serve requests and support. Retention terms can be set contractually.
Tenant isolation
Every request is authenticated to a single account, and data access is scoped per tenant so one customer can never read another customer’s keys, usage, or reports.
Incident response & breach notification
We maintain an incident-response process for security events. Where a BAA is in place, breach-notification timelines and responsibilities are defined contractually so you know exactly what to expect and when.
Secure development lifecycle
Changes go through code review and automated checks before release, and third-party dependencies are monitored for known vulnerabilities so fixes ship promptly.
Encrypted backups & resilience
Platform data is backed up on a regular schedule using encrypted storage, so records and reports can be recovered without exposing data at rest.
We’re glad to walk procurement teams through our security controls and roadmap under NDA. Developers can see how auth, per-key hashing, and audit logging work in the API documentation.
What we process, and what we return
Two kinds of data flow through the API. Knowing exactly what each one is makes compliance review straightforward.
- Public-record data
- The sex-offender records we return are public-record data. No private or protected dataset is involved at any point.
- Identifiers you submit
- To run a search you send us query inputs — typically a name and, optionally, date of birth or location. If that data is PHI in your hands (for example, a patient or applicant record), a signed BAA governs how we process it on your behalf.
- What we return
- Matches are public-record data, with source provenance and a match-confidence score. Results are informational and are not a consumer report.
- Hosting & subprocessors
- The platform runs on reputable US-based cloud infrastructure with encryption in transit and at rest. We keep the list of subprocessors that handle data on our behalf to a minimum and can provide it, along with data-residency details, during procurement or under a BAA.
Compliance questions, answered
Will Offendersearch sign a BAA?
Yes. Offendersearch will enter into a Business Associate Agreement with eligible enterprise customers who handle protected health information (PHI) in connection with our API. Request one through sales and we will scope it to your use case.
Is Offendersearch HIPAA compliant?
Offendersearch is built to support HIPAA-regulated workflows: encryption in transit and at rest, least-privilege access, hashed per-account API keys, audit logging, and tenant isolation, backed by a signed BAA. HIPAA compliance is a shared responsibility — the BAA defines each party’s obligations for the PHI you process through the API.
What is your security posture?
Enterprise-grade security throughout: encryption in transit and at rest, API keys stored only as hashes, per-account tenant isolation, and audit logging on every request. We are happy to walk procurement teams through our controls and roadmap under NDA.
What data does the API actually process?
Public-record sex-offender data derived from publicly available records, plus the identifiers you submit to run a search (such as name and date of birth). Results are public-record data and are not a consumer report.
How is my API key protected?
Each account gets its own API keys, and secrets are stored only as one-way hashes — we never keep the raw key, so a database read can never expose a usable credential. Keys can be rotated or revoked at any time, and the full secret is shown only once, at creation.
How do you handle a security incident?
We maintain an incident-response process for security events. Where a BAA is in place, it defines breach-notification timelines and each party’s responsibilities, so notification obligations are contractual rather than best-effort.
Where is data hosted, and who are your subprocessors?
The platform runs on reputable US-based cloud infrastructure with encryption in transit and at rest. We keep subprocessors to a minimum and can share the current list and data-residency details during procurement or under a BAA.
How is acceptable use governed?
Use is subject to our acceptable-use terms and applicable law, accepted at onboarding.
Both checks a care employer is asked for
Registry screening is the one most states name in statute for direct-care roles. Criminal records are what an employer is asked for on top of it. Both run on the same key, the same call and the same BAA.
Sex offender registries
58 US registries — the 50 states, DC, the territories and tribal registries — continuously updated, with photographs, aliases, addresses and a citation to the official record on every match.
Criminal records
1,375 county jail rosters, 53 statewide prison systems, 24 court sources and 28 warrant systems, with coverage in every US state.
Screening a roster rather than one hire? Batch a CSV — billed per row, same rate. Building it into an EHR or scheduling product? See the screening API.
Ready to talk compliance?
Request a BAA or get our security posture in front of your procurement team.