Security

Security & HIPAA

Last updated: September 2026 · This page lists the security controls implemented in TreatPath today, and how each one works.

The short version

TreatPath stores and processes protected health information on your practice's behalf, which makes us a business associate under HIPAA. A signed Business Associate Agreement is required before you use TreatPath with patient information. HIPAA does not certify software — your practice is the covered entity, and TreatPath is built to support your obligations rather than to replace them.

What is in place today

Where your data goes

Three outside services are involved, and we would rather name the categories plainly than bury them:

Nothing else leaves the system. We have executed Business Associate Agreements covering all four functions — database, hosting, AI and mail — each on a HIPAA-configured environment, and we will confirm their status to any practice that asks. In August 2026 we moved our application hosting onto the same covered cloud platform as the database, so that every service which can touch patient information now sits under an executed agreement.

Request a BAA

Email support@gettreatpath.com and we will send our Business Associate Agreement for your review. If your compliance officer has questions about anything on this page, we are happy to answer them directly.

Reporting a security issue

If you believe you have found a vulnerability in TreatPath, email support@gettreatpath.com with the details. We will acknowledge your report and keep you updated on the fix. Please do not access, modify or retain any data that is not yours while investigating.