Skip to content

Security

What happens to your clients' information

You are the one who has to answer for this, so it should be written plainly rather than buried in a policy nobody reads. Here is exactly what we do with protected health information, including the parts about AI.

Is it HIPAA compliant to use AI for therapy notes?

It can be, and the deciding factor is contractual rather than technical. HIPAA permits a business associate to process protected health information when a BAA is in place, access is limited to the minimum necessary, and the data is safeguarded in transit and at rest. Consumer AI chatbots fail that test because no BAA covers them. Congruent executes a BAA with you and with every subprocessor that can touch session content.

The longer version, including the questions worth asking any vendor before you hand them a session, is in our guide to AI notes and HIPAA.

01How AI touches PHI

What the AI does, and what it will never do.

Most vendor security pages describe encryption at length and go quiet on this. It is the part clinicians actually worry about, so it goes first.

  • Session content is processed to produce your note and treatment plan drafts, then the audio is deleted.

  • Every AI provider in the processing path operates under a business associate agreement with us.

  • Your notes are checked against your own chart data — the diagnosis and treatment plan you already wrote.

  • ✕

    Your clients' data is never used to train any AI model, ours or a vendor's.

  • ✕

    Your data is never sold, shared with advertisers, or used to build a dataset we license to anyone.

  • ✕

    No AI model makes a clinical decision, signs a note, or submits a claim. Every record waits for you.

The BAA is included, free, on every plan

Including during the free trial, because you cannot lawfully put real client information into a system before one is executed. Some vendors treat the BAA as a paid or enterprise-tier item. We think charging for the document that makes lawful use possible is an odd way to price software for clinicians.

02Controls

The technical safeguards, without the acronym parade.

  • Encrypted in transit and at rest

    TLS 1.2 or higher for everything moving over the network, AES-256 for everything stored. Backups are encrypted with the same standard.

  • HIPAA-eligible United States infrastructure

    Data is stored with cloud providers under a business associate agreement, in United States regions, with a signed BAA covering every subprocessor in the path.

  • Role-based access, logged

    People see only the charts their role allows. Every view, edit, and export is recorded in an audit trail you can pull yourself.

  • Multi-factor authentication

    Available on every account and required for anyone on our side with production access. No shared logins, ever.

  • Session audio deleted after drafting

    When recording is used, the audio exists only long enough to produce your note draft, and is then deleted. You can shorten that window or never record at all.

  • Export whenever you want

    Charts, signed notes, treatment plans, assessment scores, and your client list come out in standard formats at no charge, with no request process.

Where we are, stated plainly

Congruent is a new product from a small team. The controls above are in place; formal third-party attestations such as SOC 2 or HITRUST take time and independent auditors, and we are not going to imply we hold certifications we have not yet earned. If a current attestation is a requirement for your practice today, ask us where things stand before you commit — we will give you a straight answer rather than a logo.

03Security questions

What clinicians ask before trusting software with a caseload.

Is it HIPAA compliant to use AI for therapy notes?

It can be, and the deciding factor is contractual rather than technical. HIPAA permits a business associate to process protected health information when a BAA is in place, access is limited to the minimum necessary, and the data is safeguarded in transit and at rest. Consumer AI chatbots fail that test because no BAA covers them. Congruent executes a BAA with you and with every subprocessor that can touch session content.

The longer answer →
Do you record sessions, and do I need client consent?

Recording is optional and off until you turn it on for a given session. You should obtain and document client consent before recording, which is both an ethical requirement under the major professional codes and a legal one in all-party consent states; Congruent includes a consent form in the intake packet and stores the signed copy in the chart.

Where is my data stored and how is it protected?

Data is stored in HIPAA-eligible United States cloud infrastructure, encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Access is role-based and logged, production access requires multi-factor authentication, and every view or change to a chart is recorded in an audit trail you can export.

How long do you keep session audio?

Only as long as it takes to produce your note draft, after which the audio is deleted by default. You can shorten that window or turn recording off entirely and dictate instead — the note quality is nearly identical, because the model is working from your clinical language either way.

Can I get my data out?

Yes, whenever you want, without asking permission or paying a fee. Charts, signed notes, treatment plans, assessment scores, and your client list export in standard formats. A clinical record you cannot take with you is a record you do not really control.

Who can see my clients' charts inside my practice?

Only the people you grant access to. Solo accounts are single-clinician by default. On Practice plans, roles determine whether someone can view a chart, edit it, co-sign it, or only see billing information, and supervisors see exactly the caseloads assigned to them.

Read the BAA before a single chart moves.

The business associate agreement is executed as part of setting your account up, at no cost, before you enter a single client's information. Look it over with whatever scrutiny you would give any vendor contract.

30 days free · No credit card · Free migration and BAA