Security & HIPAA

Last updated July 1, 2026

gototherapy.app is built for the sensitivity of mental-health records. Security isn’t a feature bolted on — it’s how the platform is designed. Here’s what protects your practice and your clients.

HIPAA & Business Associate Agreement

We operate as a HIPAA Business Associate to the practices we serve and enter into a Business Associate Agreement (BAA) governing all protected health information. Our own infrastructure runs on Amazon Web Services under a signed AWS BAA.

Encryption

All traffic is encrypted in transit with TLS. Data at rest — databases, uploaded documents, and insurance cards — is encrypted with AWS KMS-managed keys. Uploaded files are never publicly accessible; they are served only through authenticated, access-checked requests.

Access controls

Every account is scoped to a single practice, and providers see only their own clients. Administrative functions — team management, billing, and the activity log — are restricted to admins. Sign-in is passwordless via one-time email links, and each staff member can set a personal PIN.

Automatic screen lock

After a period of inactivity the screen locks automatically, so an unattended device never leaves records exposed. Staff unlock with their personal PIN, or the session ends entirely.

Audit logging

Access to client records, document downloads, and superbill generation are recorded — who, what, and when — and admins can review the activity log at any time.

Tenant isolation

Each practice operates in its own isolated workspace on a dedicated subdomain. Data is scoped to the practice at every layer, so one practice can never reach another’s records.

Payments

Card payments are handled by Stripe. We never store full card numbers — only a secure token — and payment descriptions are kept free of clinical detail.

Questions

Security questions or want a copy of our BAA? Email hello@gototherapy.app.