Security & Compliance
HIPAA compliance isn't an add-on. It's the foundation.
Every Notes account includes a signed Business Associate Agreement, encryption at rest and in transit, and role-based access controls β standard, on every plan.
Business Associate Agreement, included automatically
As a HIPAA Business Associate to the practices that use Notes, we provide a signed BAA with every account β no separate request, no extra fee, no delay to onboarding. It outlines our shared responsibilities for protecting client health information.
- BAA generated automatically when your account is created
- Covers clinical documentation, scheduling, billing, and telehealth data
- Available for download at any time from account settings
Documentation
Encryption and access control by default
Protected health information is encrypted both at rest and in transit. Access is restricted by role β front-desk staff, billing specialists, providers, and administrators each see only what's necessary for their role, and every access event is logged for audit purposes.
- 256-bit encryption at rest and in transit
- Role-based permissions across every module
- Full audit trail of chart access, edits, and AI-assisted drafts
Access controls
Infrastructure
Built on healthcare-grade infrastructure
US-based hosting
Data is hosted with US-based infrastructure providers that maintain healthcare-grade security controls.
SOC 2 Type II (in progress)
Notes is undergoing SOC 2 Type II audit to formally validate our security, availability, and confidentiality controls.
Automated backups
Client records are backed up automatically, with disaster recovery procedures tested regularly.
Continuous monitoring
Infrastructure is monitored around the clock for unusual access patterns and potential threats.
Multi-factor authentication
Optional MFA for every user account adds a layer of protection beyond a password.
Data portability
Practices can export their full clinical, scheduling, and billing data at any time.
Questions
Security & compliance FAQ
Is Notes HIPAA compliant?+
Yes. Notes is built to support HIPAA compliance for behavioral health practices, with encryption, access controls, audit logging, and a signed BAA included on every plan.
Do you provide a Business Associate Agreement?+
Yes, automatically. A BAA is generated with every account at no extra cost and is available for download from account settings.
Where is client data stored?+
Data is stored with US-based infrastructure providers that maintain healthcare-grade physical and technical security controls.
How does TherapyFuel handle AI-assisted notes securely?+
TherapyFuel drafts are generated within the same encrypted, access-controlled environment as the rest of the chart, logged in a full audit trail, and never finalized without provider review and signature.
Can I request a security review or documentation?+
Yes. Contact us and our team can provide additional security documentation for practice or organizational review.