Security & HIPAA
Your clients' data security is our top priority.
In this guide, we'll cover:
- HIPAA compliance
- Data protection
- Your responsibilities
- Changing your password
- Trouble signing in
- Two-Factor authentication
HIPAA compliance
- BAA included — a Business Associate Agreement is automatically in effect when you create your account
- Encryption — all data is encrypted in transit (TLS) and at rest (AES-256)
- Access controls — role-based permissions ensure team members only see what they need
- Change history — every change to a client record is versioned, with who made it and when
Data protection
- Data is stored in HIPAA-eligible cloud infrastructure (AWS)
- We maintain a formal HIPAA security risk analysis with an active remediation program
- No client data is used to train AI models
- Audio recordings are processed securely and not retained beyond what's needed for transcription
Your responsibilities
- Use a strong, unique password
- Don't share your login credentials
- Log out when using shared computers
- Report any suspected security issues to support@practiceharbor.com
Changing your password
While signed in: go to Settings → Profile and use the Change Password button — enter your current password and the new one.
If you're locked out: on the sign-in page, enter your email, then click Forgot password? and follow the email link to set a new password.
Trouble signing in
"Forgot password?" email never arrives. Check spam first, and confirm you're using the address your practice invited you with — the reset only goes to an address that has an account. Team members can ask the practice owner to check the invitation address under Settings → Team.
Your invite link says it was already used. Invitation links are one-time. Ask the practice owner to resend the invitation from Settings → Team (the ⋮ menu next to your name) — a fresh link arrives by email.
Password is right but sign-in loops back. Clear the saved autofill entry and type the password by hand — browser autofill filling an old password is the usual cause. Still stuck? Try a private/incognito window; if that works, clear this site's cookies in your normal window.
Lost your authenticator device (2FA). Contact support@practiceharbor.com from the email address on your account and we'll help you regain access.
Two-Factor authentication
Each team member can turn on Two-Factor Authentication from Settings → Profile (Security section): scan the QR code with an authenticator app and codes are required at sign-in from then on. Encourage it practice-wide — it's the single highest-value account protection available.