Compliance
How BetweenSessions.care protects your clients' health information — technical, administrative, and physical safeguards.
BetweenSessions.care is a product of NeuroHarbor LLC. It is a HIPAA-compliant platform for therapists to communicate with and monitor their clients. We implement comprehensive technical, administrative, and physical safeguards to protect Protected Health Information (PHI).
ActiveAutomatically included via Microsoft Product Terms
The HIPAA BAA covers all Azure services used by BetweenSessions.care. No separate contract signature required.
RequiredPresented during subscription signup
NeuroHarbor LLC (operating BetweenSessions.care) acts as your Business Associate. Our BAA outlines our respective responsibilities for protecting PHI.
| Component | At Rest | In Transit |
|---|---|---|
| Database | TDE (Transparent Data Encryption) | TLS 1.2 |
| File Storage | AES-256 | HTTPS only, TLS 1.2 |
| Web Applications | N/A | HTTPS only, TLS 1.2 |
Comprehensive audit logging is maintained for all database operations, file access, and authentication events. Logs are retained for 6 years (2,190 days) as required by HIPAA.
PHI is only accessible to:
All infrastructure is hosted on Microsoft Azure, which maintains:
SOC 1, SOC 2, SOC 3
Certifications
ISO 27001
Certification
HIPAA Compliant
For covered services
Web app hosting: West US 2
App Service data center
AI processing: East US
Azure OpenAI resource region (see AI processing section below)
BetweenSessions.care uses AI to compile client summaries, generate pre-session prep cards, and draft clinical notes from your rough input. All AI processing runs inside the same Microsoft Azure environment that stores your data, under Microsoft's Business Associate Agreement.
Provider: Azure OpenAI Service
Deployments: gpt-4o and gpt-4o-mini
Region: East US (Azure OpenAI resource)
The Azure OpenAI resource region is separate from the App Service hosting region (West US 2). Both regions are HIPAA-eligible under Microsoft's BAA.
When a subscription is canceled, client records are archived rather than deleted, and client magic-link access is disabled. Resubscribing restores everything automatically. Archived data stays until you request deletion in writing. Deletion is completed within 90 days of a request by default, or 30 days on request, and confirmed in writing.
| Data Type | Classification |
|---|---|
| Client names and emails | PHI |
| Journal entries and images | PHI |
| Provider posts and messages | PHI |
| File attachments | PHI |
| Provider account information | PII |
As a Covered Entity using BetweenSessions.care, you acknowledge that:
For security or compliance questions, contact us at support@betweensessions.care
Last updated: December 2025