Compliance

Where we are on HIPAA, and what is left.

Compliance

HIPAA, in progress

هذه الصفحة بالإنجليزية، لأن النص الملزم قانونًا هو النص الإنجليزي. إن أردت شرحًا لها بالعربية فاكتب إلينا من صفحة التواصل وسيشرحها لك شخص.

Where we are today

24Therapy is in closed beta and is not yet HIPAA compliant. We are incorporating in the United States, and business associate agreements with each of our infrastructure providers are the next step after that, a BAA is a contract, and a contract needs a legal entity to sign it. Until every row in the table below reads signed, do not put protected health information into this product. We will tell you the day that changes rather than leaving you to check.

The subprocessors, and where each one stands

Vercel, hosting and compute. HIPAA-eligible on their Enterprise plan; BAA available; not yet signed. Neon, the database holding every clinical record. HIPAA-eligible on their Business plan; BAA available; not yet signed. OpenAI, transcription and note generation. Zero-retention and a BAA are available on their enterprise terms; not yet signed. Daily, video. HIPAA-eligible plan with a BAA available; not yet signed. Stripe, payments; a BAA is available and payment data is not PHI in our architecture, since we never see a card. Resend, transactional email; a BAA is available. Every one of these is a company we can sign with, which is why they were chosen; none of them is signed yet, which is why this page says in progress rather than compliant.

What the beta means for you

Our first customers are a small number of practices who know exactly what this is: a product being tested, priced for that, with the compliance work openly unfinished. Their patients are told too, the recording consent step is real, it stores what was agreed and when, and refusing it costs the patient nothing. If you are a US covered entity and you are not comfortable being one of those first practices, wait for the table above to go green. That is a reasonable position and we will not argue you out of it.

What is already built

None of this depends on a signature and all of it can be inspected. Access to any chart requires an authenticated, non-expired session; sessions expire after 30 minutes of inactivity and 8 hours absolute. Every read and write of clinical data is recorded in an append-only audit log with actor, patient, resource and timestamp. Passwords are stored as scrypt hashes. Video rooms are private and require a per-participant token. Patients are asked to agree to being recorded before they enter the room, and their answer is stored with a timestamp and the wording they saw. Clinicians cannot delete a patient or a session, and cannot send clinical text to an address they type.

Where your data is held

Amazon Web Services in Oregon, United States (us-west-2). If your regulator requires patient data to remain inside your own country, as the UAE does for health information under Federal Law No. 2 of 2019, this deployment does not meet that requirement, and a region inside your jurisdiction is available on request. HIPAA is a United States statute and does not itself govern a practice in Dubai or Riyadh; we are meeting the US standard first because it is the higher bar, and because clearing it makes everything that follows easier to answer.

Retention and recovery

Audit records are retained for six years. Clinical records are retained until deleted by the practice. Database point-in-time recovery currently covers the last 24 hours and will be extended before general availability.