Skip to main content

trust-and-security


Trust & Security

Choosing where your clinical notes and client records live is one of the most important decisions a solo or small therapy practice makes. This page explains, in plain language, how your data is protected — so you can make that decision with confidence.

HIPAA & your Business Associate Agreement​

We operate as a HIPAA Business Associate. A Business Associate Agreement (BAA) governs how we handle protected health information (PHI) on your behalf, and it is available to every practice at no extra cost — there is no separate "HIPAA plan" or upsell to unlock it.

  • Review the BAA — read the full agreement at any time.
  • Vendors that handle PHI on our behalf do so under business-associate safeguards, on a need-to-know basis (see Subprocessors below).

Encryption​

  • In transit — every connection to the application and its API is encrypted with TLS (HTTPS). Data moving between your browser and our servers is never sent in the clear.
  • At rest — the databases and file storage that hold your records run on managed AWS infrastructure with encryption at rest.

Where your data lives​

Your data is hosted in the United States on Amazon Web Services (AWS), a HIPAA-eligible cloud provider. The platform runs on AWS managed services:

  • A managed relational database for structured records, with full version history on every change.
  • Managed object storage (Amazon S3) for files such as documents and session audio.
  • Content is served over HTTPS, and file downloads use signed, expiring URLs rather than public links.

We self-host and operate this infrastructure directly, and we keep the platform current with security and dependency updates on a regular cadence.

Backups​

  • Automated database backups with point-in-time recovery, so the database can be restored to a specific moment rather than only to a nightly snapshot.
  • Object versioning is enabled on file storage, so a stored file that is changed or deleted can be recovered from a prior version.

Subprocessors​

These are the vendors that may receive client records, session audio, or other identifying information on your behalf, and what each one receives:

VendorPurposeData received
Amazon Web Services (AWS)Cloud hosting, database, file storage, and email delivery (US)All platform data at rest; emails the platform sends on your behalf (for example, superbill PDFs)
AnthropicAI drafting of notes, treatment plans, and summariesThe session transcript and, unless you turn on de-identification, your client's first name; treatment-plan drafting also sends name, age, and diagnoses
DeepgramSpeech-to-text transcription (default engine) and text-to-speechSession audio and the resulting transcript
GroqSpeech-to-text transcription (alternative engine you can select in Note Preferences)Session audio
LiveKitBuilt-in telehealth video infrastructureLive session audio/video while a call is in progress; participant names
StediInsurance clearinghouse (claims, eligibility, remittances)Claim and eligibility data: client name, date of birth, member ID, address, diagnosis and service codes; Social Security number when used for an eligibility check
StripePayment processingClient name and email for billing; card numbers are entered directly with Stripe and are never stored on our servers

A few services receive limited, deliberately non-clinical information:

VendorPurposeData received
AWS End User MessagingSMS appointment remindersPhone number and the message text — reminders contain the date and time only, with no client name, practice name, or clinical content
Google CalendarOptional two-way calendar syncClient initials and appointment times only — never full names or clinical details
Expo / Apple / Google push servicesMobile app notificationsShort notification text; session content and clinical details are never included
Google (reCAPTCHA, sign-in, fonts)Bot protection on public forms, optional Google sign-in, web fontsStandard web request data such as IP address and browser details; no client records
RevenueCatMobile app subscription billingSubscription and transaction identifiers only

If your practice uses its own video service (Zoom, Doxy.me, Google Meet) instead of built-in telehealth, we store and send only the join link — the session itself runs on that service, under your practice's own agreement with that vendor.

We use no advertising trackers and no third-party analytics in the application, and no client data is sold or shared for marketing.

How AI notes are handled​

If you use AI-assisted notes, here is what happens to the audio and transcript:

  • Session audio is sent to our speech-to-text vendor (Deepgram by default, or Groq if you select it) over an encrypted connection to produce a transcript.
  • Session audio is automatically purged on a short retention schedule (roughly a week) after it has been transcribed — it is not kept indefinitely.
  • The transcript is then sent to Anthropic over an encrypted connection to draft the note write-up. Drafting works from the session content you provide — it does not pull in the rest of the client's chart.
  • Session content is handled on a need-to-know basis under business-associate safeguards. By default, the draft refers to your client the way you did in session. If you prefer, an optional De-identify Names setting (in Note Preferences) keeps client names out of AI-drafted notes — it is one click to turn on.
  • Your clients' data is not used to train AI models.

For a step-by-step walkthrough of the notes workflow, see How AI notes work.

Access controls & data isolation​

  • Role-based access — team members see only what their role allows. Permissions follow the person's role in your practice rather than being all-or-nothing.
  • Per-practice data isolation — each practice's records are scoped to that practice. Access is enforced by the platform on every request, not just hidden in the interface.
  • Change history — every change to a clinical record is versioned, so edits are attributable and nothing is silently overwritten.
  • Account protections — every team member can enable two-factor authentication.

Your part​

Security is shared. The most impactful things you control:

  • Use a strong, unique password and turn on two-factor authentication.
  • Don't share logins — invite each team member with their own account.
  • Log out on shared or public computers.

Reporting a security concern​

If you believe you've found a security issue or have a question about our posture, email support@practiceharbor.com. We take reports seriously and respond quickly.