HIPAA compliance is not an add-on at Serenanote — it is built into every layer of the product. Here's exactly what we do to protect your clients' protected health information (PHI).
Encryption
- At rest: All PHI is encrypted with AES-256.
- In transit: All connections use TLS 1.3. HTTP connections are rejected.
- Database: Field-level encryption for especially sensitive data (diagnosis codes, session notes).
Access controls
- Two-factor authentication (2FA) required for all accounts.
- Automatic session timeout after inactivity.
- Role-based access — you control who sees what.
Audit logging
Every access to client records is logged with timestamp, user, and action. Logs are tamper-proof and retained for 6 years per HIPAA requirements.
Business Associate Agreements (BAA)
We sign a HIPAA-compliant BAA with every customer and with every vendor who processes PHI on our behalf, including our cloud infrastructure and AI note provider.
Data residency
All data is stored in the United States on SOC 2 Type II certified infrastructure.
Request a BAA
To request your Business Associate Agreement, email getserenanote@gmail.com. We will send it within one business day.