Compliance

HIPAA Compliance

How we protect your clients' data

HIPAA compliance is not an add-on at Serenanote — it is built into every layer of the product. Here's exactly what we do to protect your clients' protected health information (PHI).

Encryption

Access controls

Audit logging

Every access to client records is logged with timestamp, user, and action. Logs are tamper-proof and retained for 6 years per HIPAA requirements.

Business Associate Agreements (BAA)

We sign a HIPAA-compliant BAA with every customer and with every vendor who processes PHI on our behalf, including our cloud infrastructure and AI note provider.

Data residency

All data is stored in the United States on SOC 2 Type II certified infrastructure.

Request a BAA

To request your Business Associate Agreement, email getserenanote@gmail.com. We will send it within one business day.