Security & HIPAA
Your clients' data security is our top priority.
HIPAA Compliance
- BAA included — a Business Associate Agreement is automatically in effect when you create your account
- Encryption — all data is encrypted in transit (TLS) and at rest (AES-256)
- Access controls — role-based permissions ensure team members only see what they need
- Change history — every change to a client record is versioned, with who made it and when
Data Protection
- Data is stored in HIPAA-eligible cloud infrastructure (AWS)
- We maintain a formal HIPAA security risk analysis with an active remediation program
- No client data is used to train AI models
- Audio recordings are processed securely and not retained beyond what's needed for transcription
Your Responsibilities
- Use a strong, unique password
- Don't share your login credentials
- Log out when using shared computers
- Report any suspected security issues to support@practiceharbor.com
Changing Your Password
While signed in: go to Settings → Profile and use the Change Password button — enter your current password and the new one.
If you're locked out: on the sign-in page, enter your email, then click Forgot password? and follow the email link to set a new password.
Two-Factor Authentication
Each team member can turn on Two-Factor Authentication from Settings → Profile (Security section): scan the QR code with an authenticator app and codes are required at sign-in from then on. Encourage it practice-wide — it's the single highest-value account protection available.