Security

Security & HIPAA

Last updated: August 2026 · TreatPath is in beta. This page lists what is implemented today and what is still in progress, including the parts that are not finished.

The short version

TreatPath stores and processes protected health information on your practice's behalf, which makes us a business associate under HIPAA. A signed Business Associate Agreement is required before you use TreatPath with patient information. HIPAA does not certify software — your practice is the covered entity, and TreatPath is built to support your obligations rather than to replace them.

What is in place today

Where your data goes

Two outside services are involved, and we would rather name the categories plainly than bury them:

Nothing else leaves the system. We have executed Business Associate Agreements with both providers, each on a HIPAA-configured environment, and we will confirm their status to any practice that asks. A corresponding agreement with our hosting provider is in progress.

What is not finished

We would rather tell you this than have you discover it in diligence.

Request a BAA

Email support@gettreatpath.com and we will send our Business Associate Agreement for your review. If your compliance officer has questions about anything on this page, we are happy to answer them directly.

Reporting a security issue

If you believe you have found a vulnerability in TreatPath, email support@gettreatpath.com with the details. We will acknowledge your report and keep you updated on the fix. Please do not access, modify or retain any data that is not yours while investigating.