Security
Security & HIPAA
Last updated: August 2026 · TreatPath is in beta. This page lists what is implemented today and what is still in progress, including the parts that are not finished.
The short version
TreatPath stores and processes protected health information on your practice's behalf, which makes us a business associate under HIPAA. A signed Business Associate Agreement is required before you use TreatPath with patient information. HIPAA does not certify software — your practice is the covered entity, and TreatPath is built to support your obligations rather than to replace them.
What is in place today
- Encryption. All traffic uses HTTPS. Stored data is encrypted at rest by our infrastructure providers.
- Per-practice isolation. Each practice's records live under its own identity, and which practice a request belongs to is derived from a verified sign-in token rather than anything the browser can set. One practice cannot read another's data, and this is enforced by the server, not by the interface.
- Access logging. Every time a treatment plan is opened, signed, exported or changed, we record who did it, which plan, when, and from what address. The log stores the plan's reference code rather than the patient's name, so the log itself is not a second copy of your patient list.
- Automatic sign-out. Staff sessions end after 25 minutes of inactivity, with a five-minute warning first. The patient iPad clears itself two minutes after a plan is signed, and after ten minutes of no interaction on an unsigned plan, so a device passed between patients does not keep the previous one's plan on screen.
- Clean sign-out. Signing out clears the session completely, so a shared front-desk computer does not carry one user's patient data into the next user's session.
- No patient data in error monitoring. Our error reporting is configured to exclude request contents and variable values, and we test this deliberately rather than assuming it.
- Single-use access codes. Each practice receives its own activation code that works once and cannot be forwarded or reused.
- Backups. Point-in-time recovery is enabled on our database.
Where your data goes
Two outside services are involved, and we would rather name the categories plainly than bury them:
- A cloud database provider stores your treatment plans, including patient name, procedures, amounts and any captured signature.
- An AI provider receives the treatment plan image when you use the scan feature, in order to read the procedures and fees from it.
Nothing else leaves the system. We have executed Business Associate Agreements with both providers, each on a HIPAA-configured environment, and we will confirm their status to any practice that asks. A corresponding agreement with our hosting provider is in progress.
What is not finished
We would rather tell you this than have you discover it in diligence.
- Business Associate Agreements with our subprocessors are in progress and not yet executed.
- A formal written risk analysis is in progress.
- Per-user accounts within a practice. Today a practice has one login. That means our access log attributes activity to the practice rather than to an individual staff member. Per-user accounts are in development and are a prerequisite for us recommending TreatPath to practices with formal compliance programmes.
- Written policies, workforce training and an incident response plan are being prepared.
Request a BAA
Email support@gettreatpath.com and we will send our Business Associate Agreement for your review. If your compliance officer has questions about anything on this page, we are happy to answer them directly.
Reporting a security issue
If you believe you have found a vulnerability in TreatPath, email support@gettreatpath.com with the details. We will acknowledge your report and keep you updated on the fix. Please do not access, modify or retain any data that is not yours while investigating.