🔒 HIPAA Compliant Platform

HIPAA Compliance

Last updated: July 23, 2026

Our HIPAA Commitment

ABA AI is built from the ground up for healthcare providers in the ABA therapy space. We understand that the data you enter into our platform is among the most sensitive information that exists — it involves children, families, and clinical diagnoses. We take that responsibility seriously.

ABA AI operates as a HIPAA Business Associate, and we execute a Business Associate Agreement (BAA) with every clinic that uses our platform.

Business Associate Agreement (BAA)

A BAA is required under HIPAA whenever a covered entity shares PHI with a vendor or service provider. ABA AI's BAA is presented electronically during clinic onboarding and includes:

  • Permitted uses and disclosures of PHI
  • Our obligation to implement appropriate safeguards
  • Breach notification requirements (within 60 days of discovery)
  • Provisions for return or destruction of PHI upon termination
  • Obligations of our subcontractors and agents

Technical Safeguards

🔐

Encryption in Transit

All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.

💾

Encryption at Rest

All PHI stored in our database is encrypted at rest using AES-256 encryption.

👤

Access Controls

Role-based access ensures staff only see what they need. Clinic data is fully isolated from other organizations.

📋

Audit Logging

All access to PHI is logged with timestamps, user IDs, and action types for compliance review.

🏢

Clinic Isolation

Each clinic's data is logically separated. No user can access data from another clinic.

🔑

Secure Authentication

Magic link authentication eliminates password reuse risks. Session tokens expire automatically.

Administrative Safeguards

  • Designated HIPAA Privacy and Security Officers
  • Regular workforce training on HIPAA requirements
  • Access management procedures for hiring and termination
  • Periodic risk assessments and security reviews
  • Incident response and breach notification procedures
  • Vendor and subcontractor management with BAA requirements

Physical Safeguards

ABA AI is hosted on Supabase and Vercel infrastructure which maintains SOC 2 Type II compliance. Physical safeguards include:

  • Data centers with physical access controls and security monitoring
  • Redundant systems to ensure data availability
  • Secure data destruction procedures

Breach Notification

In the event of a breach involving PHI, ABA AI will:

  • Notify affected covered entities within 60 days of discovery
  • Provide details about the nature and scope of the breach
  • Describe what information was involved
  • Outline steps taken to contain the breach and prevent recurrence
  • Cooperate fully with any regulatory investigations

Your Responsibilities

  • Obtaining required patient authorizations before entering PHI
  • Managing staff access and promptly revoking access upon termination
  • Using strong, unique passwords and protecting login credentials
  • Reporting suspected breaches or security incidents to us promptly
  • Complying with your own HIPAA obligations as a covered entity
  • Ensuring devices used to access ABA AI are appropriately secured

Questions & HIPAA Contact

ABA AI HIPAA Compliance Team

Email: hipaa@aba-ai-assistant.com

We respond to all HIPAA inquiries within 2 business days.