Governed definitions, declared source authority, reconciliation of differences, and preserved lineage — so the clinical record, the billing ledger and the schedule describe the same resident day the same way. Native to SNF, AL, Memory Care and IL. Pre-production: validated in test environments, not operator-deployed.
Institutional trust markers
Multi-community operators, REITs, private equity, lenders, and multi-state portfolios evaluate the same nine markers before they sign. Each one is documented, enforced in the platform, and reviewable in the Trust-by-Design procurement package.
HIPAA-safeguarded controls; no SOC 2 certification or report claimed. No completed independent penetration-test report claimed.
HIPAA-safeguarded controls today: encryption at rest and in transit, BAA execution, PHI segregation, and signed-URL access to PHI buckets.
Operator-controlled definitions, source authority, reconciliation, and lineage across clinical, financial, workforce, compliance, and capital surfaces. Multi-tenant with database-enforced isolation.
A documented ingestion path for operator-supplied clinical, property, and accounting exports. Named-vendor connectors are ROADMAP; no third-party integration is live in operator production today. AI reads only the fields the operator declared readable.
SOC 2 in progress (underlying AWS infrastructure maintains its own SOC 2 reports), MFA required, session timeout, concurrent-session limits, continuous automated vulnerability scanning.
Immutable, append-only logs with UTC-millisecond timestamps, full user/session context, and 7-year retention.
33-role RBAC hierarchy. Property-level tenant and role gates enforced at the API layer (Fastify + tRPC on AWS) with WorkOS-authenticated sessions and defense-in-depth checks in PostgreSQL.
Holding Co → Operator → Region → Property → Unit hierarchy. Portfolio rollups computed from the Operator-Controlled Operating Record at request time. Designed for multi-state, multi-payer, multi-entity ownership.
Full detail on each marker, evidence inventory, and the Trust-by-Design procurement package live on the Trust Center.
The SeniorCRE clinical platform can serve as the operator-controlled clinical operating record for SNF, AL, Memory Care, and IL, or govern retained systems above the record they already use. It applies operator-controlled definitions, source authority, reconciliation, and lineage across resident, care plan, ledger, shift, property/unit, and entity. Outcome measurement — claims, hours, occupancy, survey readiness — is defined in a scoped validation engagement before any production commitment.
The substrate the clinical platform writes to.
How the AI surfaces read from the governed record.
Math you run on baselines your team supplies, for each of the four disciplines.
DALLAS, TX · CLINICAL BRIEF
Senior Housing & Care often inherits acute-care, post-acute, property, and workforce systems that each answer the resident-day question differently. SeniorCRE is built for the setting — PDPM, MDS 3.0, QM Engine 2026, M32 controlled substances, and Five-Star survey readiness as governed objects — while preserving the operator's choice to keep incumbent systems or deploy SeniorCRE as the clinical system of record. The differentiator is operator-controlled authority across clinical, RCM, occupancy, and workforce evidence.
Four disciplines. Operator-declared thresholds. Operator-baseline validation, never vendor-reported.

| Outcome | Metric | How it gets there |
|---|---|---|
| Claim integrity | What is recorded | Front-end claim scrubbing, payer-rule checks, MDS/PDPM accuracy guards, and controlled-substance chain-of-custody counts are recorded at the point of capture, so a claim can be traced to the care documented. SeniorCRE publishes no denial-rate figure. |
| Documentation burden | What is recorded | Ambient voice dictation, context pull-forward across the chart, and a nurse workload alert against an operator-declared utilization threshold are recorded per shift. Time returned is measured against a baseline the operator supplies, if at all. |
| Census and admissions | What is recorded | Sales pipeline stages, payer rules that lock active rooms, and the admissions and discharge lifecycle are held against the bed board the operator declares authoritative. SeniorCRE publishes no occupancy-lift figure. |
| Survey evidence | What is recorded | Append-only audit logs, QM Engine 2026 reconciliation, M32 controlled-substance shift counts, and role-based access across a granular role hierarchy make the evidence retrievable. Citation outcomes depend on operator practice, not software. |
SNF, AL, Memory Care, and IL are first-class entities — not configuration. State variation and payer rules are encoded at the database, not in a downstream report.
PDPM, MDS 3.0, Five-Star, QRP
State-specific service plans, ADL capture
Behavioral baselines, elopement protocols
Wellness, ancillary, occupancy CRM
Med passes are the highest-frequency clinical event in the building — and the most common source of survey deficiencies. The eMAR is the chain of custody.

PDPM accuracy is the difference between a defensible claim and a recoupment. When the MDS does not reflect the care actually delivered, the claim and the chart disagree — and the disagreement is discovered late.

When the care plan, the ADL assessment, and the actual care delivered live in three different systems, accuracy collapses. SeniorCRE keeps them in one.

Behavioral baselines, elopement protocols, and trigger documentation are the audit-grade core of a memory care unit. Generic EHRs reduce them to a free-text note.

Care conferences are the highest-leverage clinical meeting in the building — and the easiest to run badly. SeniorCRE puts the resident, the chart, and the family-visible summary in the same room.

Epic, R1, and Innovaccer do not serve SNF, AL, Memory Care, and IL natively. SeniorCRE is the native clinical stack for senior housing & care.
The four pillars on one record, what a recorded signal looks like before it becomes a report, how the platform maps to what 2026 buyers are buying, how a native stack differs from a retrofit, and what we will not build — all on one companion page instead of extending this one.
Read the clinical platform detailStatus as of September 29, 2026 (last modified 2026-09-29)
| Claim | Evidence step | What is true today | Proof to inspect |
|---|---|---|---|
| Operator and portfolio workspace foundation built (roles, hierarchy, entity tree). | Validated | Provisioning controls have been exercised repeatedly in controlled SeniorCRE conditions, including the operator onboarding wizard. Not yet performed for an operator in production; no standard duration is published. | Control test record; synthetic or de-identified data; no operator PHI. |
| Single-community acceptance boundary. | Architecture designed | A gate sequence derived from the migration and acceptance model. No community has gone live for an operator, so no observed duration exists. | Written deployment plan and acceptance-gate model. No execution record exists. |
| Portfolio-wide rollout acceptance across multi-community scope. | Architecture designed | A wave-cadence model from the deployment plan. Sequencing depends on community count, system count, data condition, source access, and operator authority decisions. Not a completed rollout. | Written deployment plan and acceptance-gate model. No execution record exists. |
| Connectors to PointClickCare®, MatrixCare®, Yardi®, and QuickBooks®. | Validated | Ingestion and normalization exercised against synthetic and de-identified extracts in controlled SeniorCRE conditions. No third-party integration is live in operator production. | Control test record; synthetic or de-identified data; no operator PHI. |
| Operator-Controlled Operating Record: source authority, reconciliation, field-level lineage. | Architecture designed | The Operator-Controlled Operating Record is designed and not yet implemented in any community. Authority rules, reconciliation, and field-level lineage are design intent; synthetic examples do not establish working governance. | Written deployment plan and acceptance-gate model. No execution record exists. |
| Clinical configuration: SeniorCRE as clinical system of record, or alongside an incumbent eMAR read one direction only. | Architecture designed | Designed, not built for operator use. SeniorCRE's native medication administration and eMAR are roadmap and not built; the read-only configuration alongside an incumbent eMAR depends on the Operator-Controlled Operating Record, which is designed and not yet implemented in any community. One authoritative medication record at all times is a design rule. | Written deployment plan and acceptance-gate model. No execution record exists. |
| Barcode-verified administration with an automated five-rights check at the point of medication pass. | Architecture designed | Not built. Corrected September 7, 2026: earlier pages, operator training guides, and generated answers described this control as running, which was false. Implementation boundary: four of the five medication scan surfaces open a camera preview with no decoder and match only a manually typed NDC; one mobile surface decodes frames through the browser-native BarcodeDetector API where the browser supports it (Chromium/Android; not iOS Safari, not most desktops) and compares the NDC alone. No decoding library is bundled, no surface verifies resident, dose, route, or time, and no scan result blocks an administration. The five rights are verified by the administering clinician, not by SeniorCRE. | Build-queue entry with scope and dependencies. No implementation exists. |
| Live write-back into operator payroll and scheduling systems. | Architecture designed | Specified and in the build queue. Read-side ingestion only today. | Build-queue entry with scope and dependencies. No implementation exists. |
| Implementation effort required from the operator. | Architecture designed | Deployment is staged, not effortless: platform access, source access, authority rules, reconciliation, security review, and any history migration are scoped work with operator-side effort. Any claim of zero implementation would be false. | Written deployment plan and acceptance-gate model. No execution record exists. |
Status and evidence class as of September 29, 2026. SeniorCRE has no operator-production deployment. Public timing is gate-based and operator-specific; no standard go-live duration is published. Maintained and reviewed by John Hauber, Founder, SeniorCRE, LLC. A medication-safety control was described on earlier pages as running when it was not; that correction is published in full at /medication-safety-claim.
One community, one measure you nominate (claims, hours, occupancy, or survey). Production data under NDA — never synthetic. Day-60 go / no-go against pre-agreed thresholds.
Expand to 3–5 communities with metric definitions held constant. Independent operator-baseline validation. Moral-injury and clinician-burden change tracked alongside the financial measure the operator nominates.
Portfolio rollout in phased waves. Operator-supplied clinical exports are mapped through the documented ingestion path; named-vendor connectors are ROADMAP and not live in operator production today. Unit-level signal reaches regional and capital views at the same time.
Compliance posture (audit logs, role-based access, tenant isolation, M32, QM 2026) re-validated. Override rate per AI surface reported alongside the outcome metric.
Four non-negotiables enforced on every release: HIPAA PHI buckets, immutable audit, human-in-the-loop clinical AI, no external user logins.
SeniorCRE is the operating, compliance, and asset-management layer for REITs, family offices, and institutional capital allocators in senior housing & care.