Compliance

HIPAA at Harbor

Last updated September 11, 2026

Harbor handles Protected Health Information (PHI) on behalf of therapy practices. Under the HIPAA Rules, the practice is the Covered Entity and Harbor Office, Inc. is its Business Associate. A signed Business Associate Agreement (BAA) is required before any PHI is submitted to the Service.

This page summarizes safeguards and policy requirements so that clinicians and their IT reviewers can decide whether Harbor meets their standards. For the additional scope and verification detail, see our Security page, which distinguishes requirements from evidence of performance. Harbor has not completed a third-party SOC 2 examination or obtained independent legal approval.

1. BAA status

The table reflects the agreement records maintained for these services. Actual coverage depends on the product and permitted data flow, and must be checked before a new use. We update this list in advance of changes; if any status changes materially, active Customers are notified by email.

VendorPurposeBAA
Amazon Web ServicesRDS, KMS, Cognito, S3, Chime SDK, BedrockExecuted
PauboxHIPAA-aligned transactional emailExecuted
Stedi270/271 eligibility, 837/835 claim transactionsExecuted
SignalWireVoice and SMS transportExecuted
Retell AIReal-time voice agent runtimeExecuted
Anthropic (via AWS Bedrock)LLM inference for crisis analysis and note draftingCovered under AWS BAA (Bedrock); no PHI used for training
StripeSubscription and patient payment processingPayment processor; not a general PHI-hosting service

Our vendor policy requires an applicable agreement before PHI processing; a payment processor is not thereby approved for general clinical storage.

2. Technical safeguards (§164.312)

  • Encryption at rest. The AWS database uses KMS-managed customer-managed keys (AES-256). Backups inherit the same encryption.
  • Encryption in transit. TLS 1.2 or higher is enforced on every client-facing endpoint. HSTS is enabled with a one-year max-age andincludeSubDomains.
  • Access controls. Application authentication runs on AWS Cognito with authenticator-app MFA and role-based access controls. Actual enforcement, recovery paths, and workflow coverage are verified separately.
  • Audit logs. Instrumented application events record context such as actor, time, and target. Harbor’s audit-retention policy specifies seven years; coverage and successful protected archival must be verified. HIPAA’s documentation-retention rule is not a universal medical-record retention rule. Clinical records are governed separately by applicable requirements and agreements.
  • Workstation isolation. Harbor’s policy requires named access, appropriate MFA, protected devices, and periodic review. The current account population and device attestations are evidence checked separately.

3. Administrative safeguards (§164.308)

  • Documented Security Risk Analysis reviewed annually and after material changes.
  • Workforce HIPAA training at onboarding and annually thereafter.
  • Sanction policy for workforce HIPAA violations.
  • Designated Security Officer and Privacy Officer, with assignments documented internally.
  • Incident response plan with defined roles, communication paths, and tabletop exercises.

4. Physical safeguards (§164.310)

AWS provides physical safeguards for its infrastructure. Harbor remains responsible for its workforce devices, access, and approved external services. AWS reports and the AWS BAA do not certify Harbor’s entire system.

5. Breach notification

Harbor notifies affected Customers of a suspected or confirmed Breach of Unsecured PHI without unreasonable delay and within the timeframe specified in the executed BAA. Notifications include the elements required by 45 CFR §164.410(c).

6. What we don’t do

  • We do not use PHI to train general-purpose AI models.
  • We do not load session-replay, heatmap, or behavioral-analytics tooling on the authenticated application.
  • We do not sell PHI or share it with advertising networks.
  • Harbor is not currently accepting new practices in Washington or Nevada while we work through their additional requirements. Enrollment elsewhere is subject to current availability and state-specific onboarding requirements. Confirm availability for the practice and patient locations with Harbor before starting.

7. Requesting our BAA

The full standard BAA is available on our BAA page before signup. For questions, reach out to chance@harboroffice.ai with subject line “BAA request”. Please omit patient information.

See also: Privacy Policy · Terms of Service · Security