Security & HIPAA

Built for the data therapy practices actually handle.

Harbor was engineered from day one for the realities of Protected Health Information. Every layer — infrastructure, application, operations — is designed to satisfy the HIPAA Security Rule and the expectations of clinicians, patients, and reviewers.

PHI never leaves covered ground

Every service that touches patient data is covered by an executed Business Associate Agreement. No PHI flows through any system we do not have a BAA for — the full subprocessor list is published below.

Encrypted at rest and in transit

PHI is encrypted at rest with AES-256 using managed keys, and in transit with TLS 1.2+. Backups carry the same encryption. Databases are network-isolated with no public exposure.

Nobody reads a chart unwatched

MFA on every clinician account, enforced session timeout, role-scoped access at the data layer, and append-only audit logging of every single PHI access — exportable for your own review.

Mapped to the HIPAA Security Rule.

Every required and addressable safeguard under 45 CFR §164.308–§164.312, with the specific control we use to satisfy it.

§164.308(a)(1) — Risk analysis

Annual HIPAA risk assessment, documented in our compliance binder, refreshed on every major architecture change.

§164.308(a)(3) — Workforce security

Cognito identity, role-based access, principle of least privilege. Background checks for staff with PHI access.

§164.308(a)(5) — Security awareness training

Annual HIPAA training for all team members with PHI access, completion tracked.

§164.308(a)(7) — Contingency planning

Encrypted automated daily RDS backups, 30-day retention, documented disaster-recovery runbook with periodic restoration tests.

§164.310 — Physical safeguards

No on-prem PHI. AWS data centers handle all physical controls under our BAA.

§164.312(a) — Access control

Unique account per user, automatic session timeout, MFA available on every account, audit logging on all PHI reads/writes.

§164.312(b) — Audit controls

Append-only audit log table records every PHI access with actor, timestamp, request ID. Exportable for review.

§164.312(c) — Integrity

KMS-managed encryption with integrity protection, append-only audit logs, immutable session note signing.

§164.312(e) — Transmission security

TLS 1.2+ everywhere, HSTS preload, strict CSP, no PHI in URLs, signed webhook verification on every external integration.

§164.314 — Business Associate Agreement

Signed BAA with every customer practice. Upstream BAAs executed with AWS, Paubox, Stedi, SignalWire, and Retell. Current status is on the /hipaa page.

Business Associate Agreement

Every Harbor customer signs a Business Associate Agreement before their first patient call. The BAA spells out our obligations as a business associate under HIPAA — how we handle PHI, what we’ll do in the unlikely event of a breach, and your rights to audit and terminate.

Upstream BAAs are executed with AWS, Paubox, Stedi, SignalWire, and Retell. The full, current BAA-status table is published on the HIPAA page.

Want a copy of our standard BAA template? Contact us and we’ll send it over before your demo.

Patient safety, engineered.

Harbor includes a real-time, 3-tier crisis detection system on every call and every inbound message. Tier 1 catches unambiguous warning phrases and immediately escalates with a 988 referral and an SMS to the on-call therapist. Tier 2 routes ambiguous language through a Claude Sonnet model for contextual analysis. Tier 3 monitors behavioral signals like sequential cancellations.

The system fails safe: if any model call fails, we default to escalation. Patient safety is not best-effort.

Want our security one-pager?

For your IT review or your therapy board. Just ask.

Contact Us