Last updated: July 23, 2026
ABA AI is built from the ground up for healthcare providers in the ABA therapy space. We understand that the data you enter into our platform is among the most sensitive information that exists — it involves children, families, and clinical diagnoses. We take that responsibility seriously.
ABA AI operates as a HIPAA Business Associate, and we execute a Business Associate Agreement (BAA) with every clinic that uses our platform.
A BAA is required under HIPAA whenever a covered entity shares PHI with a vendor or service provider. ABA AI's BAA is presented electronically during clinic onboarding and includes:
Encryption in Transit
All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
Encryption at Rest
All PHI stored in our database is encrypted at rest using AES-256 encryption.
Access Controls
Role-based access ensures staff only see what they need. Clinic data is fully isolated from other organizations.
Audit Logging
All access to PHI is logged with timestamps, user IDs, and action types for compliance review.
Clinic Isolation
Each clinic's data is logically separated. No user can access data from another clinic.
Secure Authentication
Magic link authentication eliminates password reuse risks. Session tokens expire automatically.
ABA AI is hosted on Supabase and Vercel infrastructure which maintains SOC 2 Type II compliance. Physical safeguards include:
In the event of a breach involving PHI, ABA AI will:
ABA AI HIPAA Compliance Team
Email: hipaa@aba-ai-assistant.com
We respond to all HIPAA inquiries within 2 business days.