Platform
Solutions
Company
Pricing
Register nowSign in

Trust

HIPAA Compliance

ProbityCare is built for behavioral health and substance use treatment, where the records are among the most sensitive in medicine. This page explains the safeguards we maintain as your business associate.

Last updated August 22, 2026Version 3.0

This page is a plain-language overview of how ProbityCare Solutions Inc. protects Protected Health Information. It is not the contract. The binding commitments are in our Business Associate Agreement, which every customer organization enters into with us.

1Our role under HIPAA

Your organization is the covered entity. It holds the direct relationship with the patient, owns the medical record, and issues the Notice of Privacy Practices.

ProbityCare is a business associate. We create, receive, maintain, and transmit PHI on your behalf in order to provide intake, clinical documentation, billing, revenue cycle, and workforce functions. We use PHI only to deliver those services, as permitted by the BAA, or as required by law.

Four commitments that do not change

  • We never sell PHI and never accept remuneration in exchange for it.
  • We never use PHI for marketing, fundraising, or advertising, ours or anyone else’s.
  • We never use PHI to train external AI models.
  • Your records remain yours, and you can export them at any time.

2Shared responsibility

HIPAA compliance is not something a vendor can supply on its own. The platform provides the controls; your organization configures and operates them. Here is the split:

ProbityCare providesEncryption, access control mechanisms, audit logging, backup and recovery, infrastructure security, subprocessor management, breach notification to you, and the signed BAA.
Your organization providesUser provisioning and offboarding, role assignment on a least-privilege basis, periodic access reviews, workstation and device security, patient consent and authorization, your own Notice of Privacy Practices, retention decisions, and review of audit reports.

We give you the tooling to hold up your side — role templates, access review exports, and audit log search — but the operational decisions are yours to make.

3Administrative safeguards

  • Security management process. A documented risk analysis is performed at least annually and after any significant change to the environment, with a tracked risk management plan.
  • Assigned security responsibility. Named Security Officer and Privacy Officer accountable for the program.
  • Written policies. Policies and procedures covering privacy, security, access management, incident response, sanctions, device and media controls, and contingency planning, reviewed at least annually.
  • Business associate management. A signed BAA is in place with every subcontractor that touches PHI, imposing the same restrictions we accept.
  • Information system activity review. Regular review of access reports, audit logs, and security incident tracking.

4Technical safeguards

ControlHow we implement it
Encryption in transitTLS 1.2 or higher for all connections, with modern cipher suites and HSTS.
Encryption at restAES-256 for databases, object storage, and backups.
Access controlUnique named accounts, mandatory multi-factor authentication, role-based permissions, and row-level authorization so records are scoped to the organization and program that owns them.
Audit controlsImmutable, timestamped logging of record access, modification, export, and administrative changes, searchable by user, patient, and date range.
IntegrityVersioned clinical documentation with amendment history, signature attribution, and no destructive edits to signed notes.
AuthenticationPassword policy aligned to NIST SP 800-63B, credential-stuffing protection, rate limiting, and automatic session timeout.
Transmission securitySecure internal messaging, encrypted claim and lab exchange, and no PHI in email or SMS notifications.

5Physical safeguards

The platform runs on cloud infrastructure in United States data centers operated by providers who maintain SOC 2 Type II and ISO 27001 certification, with 24/7 staffing, biometric access control, video surveillance, and environmental protection. We do not operate our own data centers.

  • All PHI is stored and processed within the United States. We do not transfer PHI offshore.
  • Workstation security. Company devices are encrypted, centrally managed, screen-locked, and remotely wipeable.
  • Media disposal. Decommissioned media is cryptographically erased or destroyed by the infrastructure provider under certificate.

6Substance use records under 42 C.F.R. Part 2

Stricter than HIPAA

Records from a federally assisted substance use disorder program carry protections beyond HIPAA. Most disclosures require written patient consent, redisclosure is prohibited without further consent, and the records generally cannot be used in legal proceedings against the patient without a court order.

The platform is built with these rules in mind:

  • Consent capture and expiry tracking, so a disclosure cannot be made under a lapsed consent.
  • Program-level segmentation, so Part 2 records are visible only to staff with a role that permits it.
  • The required prohibition-on-redisclosure notice attached to qualifying disclosures.
  • Disclosure logging that supports the accounting obligations introduced by the CARES Act alignment of Part 2 with HIPAA.

Determining whether your program is subject to Part 2, and obtaining valid consent, remains your organization’s responsibility. We provide the mechanism; you make the determination.

7Minimum necessary

We limit our request, use, and disclosure of PHI to the minimum necessary to accomplish the purpose. In practice that means engineering and support staff do not have standing access to customer records.

  • Production access requires an approved, time-boxed request tied to a specific support ticket or incident.
  • Every access is logged, attributed, and reviewed.
  • Non-production environments use synthetic or de-identified data. Production PHI is never copied into development or test systems.

8Workforce and training

  • Background checks before hire, to the extent permitted by law.
  • Signed confidentiality agreements covering PHI for all personnel and contractors.
  • HIPAA and security awareness training at onboarding and annually, with role-specific training for engineering and support, plus phishing simulation.
  • A documented sanction policy, up to and including termination, for violations.
  • Access is revoked as part of the offboarding checklist on the last day of employment.

9Subprocessors

We use a deliberately small set of subprocessors. Each one that handles PHI has signed a business associate agreement imposing the same obligations we accept, and each is restricted to United States regions.

SubprocessorFunctionPHILocation
SupabasePrimary database, authentication, and file storage for the platformYes — BAA in placeUnited States
VercelApplication hosting and content deliveryYes — BAA in placeUnited States
Google (Analytics)Aggregate traffic measurement on the public marketing website onlyNoUnited States
Microsoft (Clarity)Heatmaps and session replay on the public marketing website onlyNoUnited States

Optional integrations you enable

The admin portal lets you switch on integrations such as clearinghouse claim submission, laboratory results, e-prescribing, communications, and payment processing. These run under vendor accounts that ProbityCare holds rather than credentials you supply, so any of them that handles PHI is our subprocessor: we sign the downstream business associate agreement, and the vendor is bound by the same obligations listed above. Enabling an integration authorizes that specific disclosure; leaving it off means no data is shared with that vendor.

Current integration list

Because the available integrations change as we add them, we maintain the current list — including which vendor backs each one and whether it receives PHI — outside this page. Email security@probitycare.com for the current version, or check the integrations screen in your admin portal, where each connector names its vendor before you enable it.

If you would rather contract with a vendor directly under your own agreement, tell us and we will confirm whether that integration supports customer-supplied credentials. We will give customers at least 30 days notice before adding a subprocessor that will handle PHI. To receive those notices, email security@probitycare.com.

10Analytics and PHI never mix

Website analytics is a common source of accidental PHI disclosure across the industry — typically when a tracking script is left running on an authenticated page and captures a URL, form field, or on-screen record.

How we prevent it

  • Google Analytics and Microsoft Clarity load only on the public marketing website, never on any authenticated route of the platform.
  • Both are blocked until a visitor opts in through the consent banner.
  • Clarity runs with text input masking enabled, so typed content is not recorded.
  • Advertising identifiers, Google Signals, and remarketing are disabled, so no audience can be built from visits.
  • Application URLs never contain patient identifiers in query strings that could leak through a referrer header.

Full detail on what these tools collect is in our Privacy Policy.

11Breach and incident response

We maintain a documented, tested incident response plan. Our contractual notification commitments are:

3 business daysWritten report to you of any security incident or use or disclosure of PHI not permitted by the BAA.
30 calendar daysWritten report of a reportable breach of unsecured PHI, without unreasonable delay after discovery.

Our report will include, to the extent known:

  • What happened, and the date of the incident and of discovery.
  • The categories of PHI involved and the individuals affected.
  • What we have done to investigate, mitigate, and contain the incident.
  • Steps we recommend you take, and what we are doing to prevent recurrence.

You remain responsible for the notifications required under the HIPAA Breach Notification Rule to affected individuals, the Secretary of Health and Human Services, and where applicable the media. We will provide the information and cooperation you need to make them.

Suspect an incident? Contact security@probitycare.com immediately. We monitor this address continuously.

12Supporting patient rights

Patients exercise their HIPAA rights through your organization, not through us. Where we hold PHI in a Designated Record Set on your behalf, we support you within these timeframes:

AccessPHI made available for inspection and copying within 15 days of your request.
AmendmentAmendments applied within 15 days, with the original preserved in the amendment history.
AccountingDisclosure information provided within 30 days of your request.
RestrictionsConfiguration support for agreed restrictions and confidential communication preferences.

13Backup, recovery, and continuity

  • Automated encrypted backups with point-in-time recovery.
  • Geographically separated backup storage within the United States.
  • Restore procedures tested at least annually.
  • A documented contingency plan covering data backup, disaster recovery, and emergency mode operation so clinical staff retain access to records during a disruption.

14Assessments and audits

  • Annual HIPAA Security Rule risk analysis with a tracked remediation plan.
  • Annual third-party penetration test of the application and infrastructure.
  • Continuous dependency and vulnerability scanning with defined remediation windows.
  • Annual review of all policies, procedures, and subprocessor agreements.

Customers and prospective customers under NDA may request our current security documentation package, including risk analysis summary, penetration test attestation, and policy index, by emailing security@probitycare.com.

15Requesting a Business Associate Agreement

A BAA is required before any PHI enters the platform. Our standard Business Associate Agreement is entered into when your account is created, and it covers the great majority of customers without modification.

If your organization requires its own BAA form, or negotiated terms, email legal@probitycare.com with the document and we will review it. We will not accept PHI until a BAA is executed.

16Report a concern

Security and privacy contacts

ProbityCare Solutions Inc.2125 Biscayne Blvd, Ste 303
Miami, FL 33137
Security incidents: security@probitycare.com
Privacy questions: privacy@probitycare.com
Legal and BAAs: legal@probitycare.com

Security researchers are welcome to report vulnerabilities to security@probitycare.com. Please do not access, modify, or exfiltrate any data that is not your own, and give us a reasonable opportunity to remediate before disclosure. We will not pursue action against researchers who follow these guidelines in good faith.

You may also file a complaint with the HHS Office for Civil Rights. We do not retaliate against anyone who files a complaint.

17Revision history

  • Version 3.0. First publication of this overview as a standalone page, separated from the legal text of the BAA. Adds the shared responsibility model, the control inventory, 42 C.F.R. Part 2 handling, the subprocessor list with a 30-day change notice, the analytics separation policy, and the assessment schedule.