Security & Compliance

HIPAA compliance isn't an add-on. It's the foundation.

Every Notes account includes a signed Business Associate Agreement, encryption at rest and in transit, and role-based access controls β€” standard, on every plan.

πŸ”’ HIPAA-compliant
πŸ“„ Signed BAA included
πŸ‡ΊπŸ‡Έ US-based data hosting
🧾 SOC 2 Type II in progress
πŸ”— 256-bit encryption
πŸ“‹ Full audit logging

Business Associate Agreement, included automatically

As a HIPAA Business Associate to the practices that use Notes, we provide a signed BAA with every account β€” no separate request, no extra fee, no delay to onboarding. It outlines our shared responsibilities for protecting client health information.

  • BAA generated automatically when your account is created
  • Covers clinical documentation, scheduling, billing, and telehealth data
  • Available for download at any time from account settings

Documentation

Encryption and access control by default

Protected health information is encrypted both at rest and in transit. Access is restricted by role β€” front-desk staff, billing specialists, providers, and administrators each see only what's necessary for their role, and every access event is logged for audit purposes.

  • 256-bit encryption at rest and in transit
  • Role-based permissions across every module
  • Full audit trail of chart access, edits, and AI-assisted drafts

Access controls

Infrastructure

Built on healthcare-grade infrastructure

πŸ‡ΊπŸ‡Έ

US-based hosting

Data is hosted with US-based infrastructure providers that maintain healthcare-grade security controls.

🧾

SOC 2 Type II (in progress)

Notes is undergoing SOC 2 Type II audit to formally validate our security, availability, and confidentiality controls.

πŸ”

Automated backups

Client records are backed up automatically, with disaster recovery procedures tested regularly.

πŸ•΅οΈ

Continuous monitoring

Infrastructure is monitored around the clock for unusual access patterns and potential threats.

πŸ”‘

Multi-factor authentication

Optional MFA for every user account adds a layer of protection beyond a password.

πŸ“€

Data portability

Practices can export their full clinical, scheduling, and billing data at any time.

Questions

Security & compliance FAQ

Is Notes HIPAA compliant?+

Yes. Notes is built to support HIPAA compliance for behavioral health practices, with encryption, access controls, audit logging, and a signed BAA included on every plan.

Do you provide a Business Associate Agreement?+

Yes, automatically. A BAA is generated with every account at no extra cost and is available for download from account settings.

Where is client data stored?+

Data is stored with US-based infrastructure providers that maintain healthcare-grade physical and technical security controls.

How does TherapyFuel handle AI-assisted notes securely?+

TherapyFuel drafts are generated within the same encrypted, access-controlled environment as the rest of the chart, logged in a full audit trail, and never finalized without provider review and signature.

Can I request a security review or documentation?+

Yes. Contact us and our team can provide additional security documentation for practice or organizational review.

Questions about compliance for your practice?