Skip to main content

Security & HIPAA

Your clients' data security is our top priority.

HIPAA Compliance

  • BAA included — a Business Associate Agreement is automatically in effect when you create your account
  • Encryption — all data is encrypted in transit (TLS) and at rest (AES-256)
  • Access controls — role-based permissions ensure team members only see what they need
  • Change history — every change to a client record is versioned, with who made it and when

Data Protection

  • Data is stored in HIPAA-eligible cloud infrastructure (AWS)
  • We maintain a formal HIPAA security risk analysis with an active remediation program
  • No client data is used to train AI models
  • Audio recordings are processed securely and not retained beyond what's needed for transcription

Your Responsibilities

  • Use a strong, unique password
  • Don't share your login credentials
  • Log out when using shared computers
  • Report any suspected security issues to support@practiceharbor.com

Changing Your Password

While signed in: go to Settings → Profile and use the Change Password button — enter your current password and the new one.

If you're locked out: on the sign-in page, enter your email, then click Forgot password? and follow the email link to set a new password.

Two-Factor Authentication

Each team member can turn on Two-Factor Authentication from Settings → Profile (Security section): scan the QR code with an authenticator app and codes are required at sign-in from then on. Encourage it practice-wide — it's the single highest-value account protection available.