Our Commitment to HIPAA ComplianceEasyTheraNotes is designed, built, and maintained in full compliance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and all subsequent amendments, including the HITECH Act, the Omnibus Rule of 2013, and the proposed 2025–2026 Security Rule updates.
1. Overview of HIPAA Rules
EasyTheraNotes complies with the following core HIPAA regulations:
- Privacy Rule (45 CFR Part 164, Subparts A & E): Governs the use and disclosure of Protected Health Information (PHI). We adhere to the Minimum Necessary Standard, ensuring only the PHI strictly necessary for a given purpose is accessed or disclosed.
- Security Rule (45 CFR Part 164, Subparts A & C): Requires administrative, technical, and physical safeguards for electronic PHI (ePHI). We implement all required safeguards as outlined in this policy.
- Breach Notification Rule (45 CFR Part 164, Subpart D): Mandates notification procedures in the event of an impermissible use or disclosure of unsecured PHI.
- Enforcement Rule: Establishes compliance requirements, investigation procedures, and civil and criminal penalties for HIPAA violations.
2. 2025–2026 Regulatory Updates
EasyTheraNotes proactively aligns with the latest HIPAA regulatory changes:
- HHS Security Rule NPRM (January 2025): We are aligned with the proposed updates that remove the distinction between "required" and "addressable" safeguards — all safeguards are treated as mandatory in our systems.
- Mandatory Multi-Factor Authentication (MFA): All access to ePHI requires MFA via AWS Cognito.
- Mandatory Encryption: All ePHI is encrypted at rest (AES-256) and in transit (TLS 1.2+), consistent with the proposed rule making encryption a required safeguard.
- Reduced PHI Access Timeline: We are prepared to comply with the proposed reduction from 30 days to 15 days for patient access requests.
- Notice of Privacy Practices (NPP): Our NPP has been revised in compliance with the February 16, 2026 deadline.
- 42 CFR Part 2 Alignment: Full compliance with integrated substance use disorder records regulations by February 16, 2026.
3. Administrative Safeguards
We maintain the following administrative safeguards:
- Security Management Process: Comprehensive risk analysis, risk management, sanction policies, and information system activity review conducted regularly.
- Designated Security Officer: A HIPAA Security Officer is responsible for overseeing all security policies and procedures.
- Workforce Security: Authorization and supervision procedures, clearance checks, and termination protocols are in place.
- Information Access Management: Role-based access control ensures minimum necessary access based on job function.
- Security Awareness & Training: All personnel receive HIPAA training covering security protocols, phishing awareness, password management, and incident reporting.
- Contingency Planning: Data backup, disaster recovery, and emergency mode operation plans are maintained and tested regularly.
- Periodic Evaluations: Technical and non-technical evaluations of security policies are performed annually.
4. Technical Safeguards
- Access Controls: Unique user identification via AWS Cognito, emergency access procedures, automatic session logoff, and encryption/decryption of ePHI.
- Audit Controls: Comprehensive logging and monitoring via AWS CloudWatch and CloudTrail to record and examine all access to ePHI.
- Integrity Controls: Mechanisms to authenticate ePHI and protect against improper alteration or destruction.
- Person or Entity Authentication: Multi-factor authentication verifies identity before granting access to any ePHI.
- Transmission Security: All data transmitted over networks is encrypted using TLS 1.2 or higher with integrity controls.
- Encryption at Rest: All stored ePHI is encrypted using AES-256 encryption (DynamoDB encryption, S3 server-side encryption).
5. Physical Safeguards
- AWS Data Centers: All data is hosted on Amazon Web Services infrastructure with SOC 2 Type II and ISO 27001 certifications, biometric access controls, 24/7 monitoring, and environmental controls.
- Facility Access Controls: Physical access to servers is managed entirely by AWS with industry-leading security measures.
- Device and Media Controls: Policies for disposal, re-use, accountability, and backup of media containing ePHI.
6. AI Processing & PHI Protection
EasyTheraNotes uses artificial intelligence to assist with clinical documentation. We implement the following safeguards for AI-related PHI processing:
- Business Associate Agreements with AI Providers: BAAs are executed with both OpenAI and Google Cloud (Vertex AI) covering all API services that process PHI.
- Data Minimization: Only the minimum necessary PHI is sent to AI models for note generation.
- Zero Data Retention by AI Vendors: PHI is not stored by our AI providers after processing. Both OpenAI's API and Google Cloud's Vertex AI operate under zero-retention policies when covered by a BAA.
- No Training on PHI: PHI is contractually prohibited from being used to train AI models by any provider.
- Audio Processing: Audio recordings are processed for transcription with OpenAI transcription models under BAA and permanently deleted once the note is generated. No long-term audio storage occurs.
- AI Audit Trail: All AI interactions involving PHI are logged for compliance and audit purposes.
- Prompt Security: PHI is never included in system-level prompts. Patient data is transmitted only in user-level API calls with appropriate encryption and access controls.
7. Telehealth & Video Conferencing Security
EasyTelehealth provides HIPAA-compliant video conferencing with the following safeguards:
- Amazon Chime SDK: Video sessions are powered by Amazon Chime SDK, a HIPAA-eligible AWS service covered under the AWS BAA. All media streams are encrypted in transit.
- No Recording or Storage: Video from telehealth sessions is never recorded. Call audio is recorded only when the clinician turns on the optional automatic note for that session and the client consents on the join page; the recording is used only to generate the note and is deleted once the note is generated (and automatically within 24 hours in any case).
- Session Isolation: Each telehealth session creates a unique meeting with unique credentials. Session links expire when the session ends and cannot be reused.
- Session Notes: Notes taken during telehealth sessions are stored with the same encryption and access controls as all other clinical data (AES-256 at rest, TLS 1.2+ in transit).
- Session Metadata: Only minimal metadata is retained (patient name, session duration, date) for 30 days via automated TTL expiration.
- Access Controls: Only the therapist who created the session can access session notes and history. Patient join pages do not expose any PHI beyond the therapist's name.
8. Business Associate Agreements (BAAs)
EasyTheraNotes maintains Business Associate Agreements with all third-party vendors that create, receive, maintain, or transmit ePHI:
- Amazon Web Services (AWS): Covers DynamoDB, S3, Cognito, SES, CloudWatch, and Amazon Chime SDK (video conferencing) services.
- OpenAI: Covers API services used for clinical note generation and audio transcription.
- Google Cloud (Vertex AI): Covers Vertex AI services used for advanced AI processing and clinical data analysis.
All BAAs include provisions for permissible uses and disclosures of PHI, obligation to implement appropriate safeguards, breach notification obligations, subcontractor compliance requirements, and return or destruction of PHI at contract termination.
9. Patient Rights Under HIPAA
Patients whose information is processed through EasyTheraNotes retain the following rights:
- Right to Access PHI: Patients may request copies of their health information. We support timely fulfillment within 15 business days.
- Right to Amend PHI: Patients may request corrections to their health records.
- Right to an Accounting of Disclosures: Patients may request a log of when and to whom their PHI was disclosed.
- Right to Request Restrictions: Patients may request limits on uses or disclosures of their PHI.
- Right to Confidential Communications: Patients may request PHI be communicated via alternative means or locations.
- Right to Receive Notice of Privacy Practices: Patients are entitled to an updated Notice of Privacy Practices explaining their rights and data protection measures.
10. Breach Notification Procedures
In the event of a breach of unsecured PHI, EasyTheraNotes follows these notification procedures:
- Risk Assessment: A four-factor assessment is conducted to determine the nature and extent of the breach, including the types of PHI involved, the unauthorized person who accessed the data, whether PHI was actually acquired or viewed, and the extent of risk mitigation.
- Individual Notification: Affected individuals are notified within 60 days of breach discovery via written notice.
- HHS Notification: The U.S. Department of Health and Human Services is notified within 60 days for breaches affecting 500 or more individuals, or annually for smaller breaches.
- Media Notification: If 500 or more residents of a single state or jurisdiction are affected, prominent media outlets are notified.
- Incident Response: A documented incident response plan guides identification, containment, investigation, and remediation of all breaches.
- Documentation: All breach investigations and determinations are documented and retained for a minimum of 6 years.
11. Data Retention & Disposal
- Audio & Uploaded Files: Deleted immediately after AI processing is complete. No long-term storage of raw audio or uploaded documents.
- Telehealth Sessions: No audio or video is ever recorded or stored. Session metadata and notes are retained for 30 days with automated TTL expiration.
- Clinical Notes: AI-generated session notes (SOAP notes) are archived in the patient record and retained for as long as the account is active.
- Transient Data: Automated expiration (TTL) is applied to transient data such as session processing records, telehealth metadata, and email logs.
- Account Termination: Upon termination of service, all associated data is deleted from our systems.
12. Cloud Infrastructure & Security Certifications
- AWS HIPAA Eligible Services: All ePHI is processed and stored using HIPAA-eligible AWS services including DynamoDB, S3, Cognito, SES, CloudWatch, and Amazon Chime SDK.
- Encryption: AES-256 encryption at rest and TLS 1.2+ encryption in transit for all data.
- Authentication: AWS Cognito with multi-factor authentication support.
- Network Security: VPC isolation, security groups, and Web Application Firewall (WAF) protections.
- Monitoring & Logging: CloudWatch and CloudTrail provide comprehensive audit trails.
- Backup & Recovery: Automated DynamoDB backups with point-in-time recovery capabilities.
- Google Cloud (Vertex AI): AI processing via Vertex AI operates under Google Cloud's HIPAA BAA with enterprise-grade security, encryption, and compliance certifications.
- Certifications: AWS infrastructure is SOC 2 Type II and ISO 27001 certified. Google Cloud is SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, and HITRUST CSF certified.
13. Risk Assessment & Compliance Program
- Annual Risk Analysis: Comprehensive risk assessments per 45 CFR 164.308(a)(1)(ii)(A) are conducted annually.
- Risk Management Plan: Documented measures to reduce identified risks to reasonable and appropriate levels.
- Vulnerability Assessments: Regular technical assessments including vulnerability scanning.
- Policy Review: Annual review and update of all HIPAA policies and procedures.
- Incident Tracking: All security incidents and remediation actions are logged and monitored.
- Cyber Liability Insurance: EasyTheraNotes maintains active cyber liability insurance coverage to protect against data breach costs, incident response expenses, and related liabilities.
14. Disaster Recovery Plan
EasyTheraNotes maintains a documented Disaster Recovery Plan (DRP) to ensure continuity of service and protection of ePHI in the event of a disaster or system failure:
- Recovery Point Objective (RPO): Minimal data loss target. DynamoDB Point-in-Time Recovery (PITR) enables restoration to any second within the last 35 days. S3 versioning preserves all object versions.
- Recovery Time Objective (RTO): Target restoration of full service within 4 hours of a declared disaster, with critical functions restored within 1 hour.
- Automated Backups: DynamoDB continuous backups with PITR enabled on all tables containing ePHI. S3 cross-region replication for document storage. Database snapshots taken daily and retained for 35 days.
- Infrastructure Recovery: EC2 instances can be rapidly redeployed using Infrastructure as Code. Application containers managed via PM2 with automatic restart capabilities. DNS failover configured for rapid traffic redirection.
- Data Restoration Procedures: Documented step-by-step procedures for restoring DynamoDB tables from PITR backups, recovering S3 objects from versioned storage, and redeploying application services from source control.
- Communication Plan: Defined notification procedures during a disaster event, including escalation paths, responsible personnel, and communication channels for notifying affected users and stakeholders.
- Testing Schedule: Disaster recovery procedures are tested at least annually, including backup restoration verification, failover testing, and full recovery simulations. Test results are documented and used to improve the plan.
- AWS Multi-AZ Architecture: Services are deployed across multiple AWS Availability Zones to ensure high availability and automatic failover in the event of a single zone failure.
15. Contact Information
For questions about our HIPAA compliance practices, to submit a PHI access or amendment request, or to report a suspected breach, please contact: