Compliance

HIPAA safeguards.

How BetweenSessions.care protects your clients' health information — technical, administrative, and physical safeguards.

BetweenSessions.care is a product of NeuroHarbor LLC. It is a HIPAA-compliant platform for therapists to communicate with and monitor their clients. We implement comprehensive technical, administrative, and physical safeguards to protect Protected Health Information (PHI).

Business Associate Agreements

Microsoft Azure BAA

ActiveAutomatically included via Microsoft Product Terms

The HIPAA BAA covers all Azure services used by BetweenSessions.care. No separate contract signature required.

NeuroHarbor LLC BAA for Providers

RequiredPresented during subscription signup

NeuroHarbor LLC (operating BetweenSessions.care) acts as your Business Associate. Our BAA outlines our respective responsibilities for protecting PHI.

Technical Safeguards

Encryption

ComponentAt RestIn Transit
DatabaseTDE (Transparent Data Encryption)TLS 1.2
File StorageAES-256HTTPS only, TLS 1.2
Web ApplicationsN/AHTTPS only, TLS 1.2

Access Controls

  • Unique User Identification: Providers use email + password plus mandatory two-factor authentication. Clients use secure magic link authentication.
  • Mandatory Two-Factor Authentication: Every provider account must enroll a TOTP authenticator. Recovery codes are issued once at enrollment.
  • Role-Based Access: Providers only see their own clients. Clients only see their own data.
  • 60-Minute Idle Timeout: Inactive sessions are signed out automatically after 60 minutes, with a 2-minute warning before sign-out.

Audit Controls

Comprehensive audit logging is maintained for all database operations, file access, and authentication events. Logs are retained for 6 years (2,190 days) as required by HIPAA.

Administrative Safeguards

Data Access Policy

PHI is only accessible to:

  • The provider who created the client relationship
  • The client themselves
  • BetweenSessions.care system administrators (for support/maintenance only)

Physical Safeguards

All infrastructure is hosted on Microsoft Azure, which maintains:

SOC 1, SOC 2, SOC 3

Certifications

ISO 27001

Certification

HIPAA Compliant

For covered services

Web app hosting: West US 2

App Service data center

AI processing: East US

Azure OpenAI resource region (see AI processing section below)

AI Processing

BetweenSessions.care uses AI to compile client summaries, generate pre-session prep cards, and draft clinical notes from your rough input. All AI processing runs inside the same Microsoft Azure environment that stores your data, under Microsoft's Business Associate Agreement.

Service and models

Provider: Azure OpenAI Service

Deployments: gpt-4o and gpt-4o-mini

Region: East US (Azure OpenAI resource)

The Azure OpenAI resource region is separate from the App Service hosting region (West US 2). Both regions are HIPAA-eligible under Microsoft's BAA.

Data boundaries

  • PHI stays inside Azure. Prompts and completions are exchanged only with the Azure OpenAI resource inside your covered Azure environment. No PHI is sent to the public OpenAI API, to ChatGPT, or to any other third party.
  • No foundation-model training. Azure OpenAI's foundation models are pre-trained and static. Your prompts and completions are not used to train, fine-tune, or improve them. Nothing you send is shared across customers.
  • Compilation, not diagnosis. The AI compiles and cross-references what your clients and you have already written. It does not diagnose, does not make clinical recommendations, and does not act autonomously.

Data retention on cancellation

When a subscription is canceled, client records are archived rather than deleted, and client magic-link access is disabled. Resubscribing restores everything automatically. Archived data stays until you request deletion in writing. Deletion is completed within 90 days of a request by default, or 30 days on request, and confirmed in writing.

Data We Protect

Data TypeClassification
Client names and emailsPHI
Journal entries and imagesPHI
Provider posts and messagesPHI
File attachmentsPHI
Provider account informationPII

Your Responsibilities

As a Covered Entity using BetweenSessions.care, you acknowledge that:

  • You are a Covered Entity under HIPAA
  • You will only use the platform for legitimate healthcare purposes
  • You will maintain appropriate safeguards on your own devices and accounts
  • You will report any suspected security incidents to support@betweensessions.care

Questions?

For security or compliance questions, contact us at support@betweensessions.care

Last updated: December 2025