Skip to main content

Security & HIPAA

Your clients' data security is our top priority.

In this guide, we'll cover:

HIPAA compliance​

  • BAA included — a Business Associate Agreement is automatically in effect when you create your account
  • Encryption — all data is encrypted in transit (TLS) and at rest (AES-256)
  • Access controls — role-based permissions ensure team members only see what they need
  • Change history — every change to a client record is versioned, with who made it and when

Data protection​

  • Data is stored in HIPAA-eligible cloud infrastructure (AWS)
  • We maintain a formal HIPAA security risk analysis with an active remediation program
  • No client data is used to train AI models
  • Audio recordings are processed securely and not retained beyond what's needed for transcription

Your responsibilities​

  • Use a strong, unique password
  • Don't share your login credentials
  • Log out when using shared computers
  • Report any suspected security issues to support@practiceharbor.com

Changing your password​

While signed in: go to Settings → Profile and use the Change Password button — enter your current password and the new one.

If you're locked out: on the sign-in page, enter your email, then click Forgot password? and follow the email link to set a new password.

Trouble signing in​

"Forgot password?" email never arrives. Check spam first, and confirm you're using the address your practice invited you with — the reset only goes to an address that has an account. Team members can ask the practice owner to check the invitation address under Settings → Team.

Your invite link says it was already used. Invitation links are one-time. Ask the practice owner to resend the invitation from Settings → Team (the ⋮ menu next to your name) — a fresh link arrives by email.

Password is right but sign-in loops back. Clear the saved autofill entry and type the password by hand — browser autofill filling an old password is the usual cause. Still stuck? Try a private/incognito window; if that works, clear this site's cookies in your normal window.

Lost your authenticator device (2FA). Contact support@practiceharbor.com from the email address on your account and we'll help you regain access.

Two-Factor authentication​

Each team member can turn on Two-Factor Authentication from Settings → Profile (Security section): scan the QR code with an authenticator app and codes are required at sign-in from then on. Encourage it practice-wide — it's the single highest-value account protection available.