← PracticeDocket

Security

Last updated: September 14, 2026 · plain answers to the questions a therapist should ask any software that holds a client's record

Encrypted at rest and in transitEvery record under a dedicated key; every connection over TLS.
Second factor requiredEvery practitioner sign-in needs an authenticator app, not just a password.
Your data is never used to train AINot by us, and not by the vendors we use — by contract.
Every access is loggedWho opened what, when — visible to the practice.

1. Where your data lives

PracticeDocket runs on a major US cloud provider, in the United States. Client records are stored in a database encrypted with a key dedicated to PracticeDocket, with continuous backups that let us restore to any moment in the previous 35 days. Session audio, where a practice chooses to record, is stored encrypted and deleted automatically after the retention period (90 days by default) or the moment the practitioner purges it.

Each practice's data is isolated. A practitioner's sign-in reaches their practice and nothing else; that boundary is enforced in the data layer, not by convention.

2. Who else touches it

We use a small number of vendors, each under a Business Associate Agreement where they can see protected health information. We send them as little as the job needs. By function, and in every case the least the job allows:

What forWhat they seeBAA
Hosting, database and text-message deliveryEncrypted storage; text bodies carry no clinical contentYes
Email deliveryAppointment, form and invoice emails — no clinical contentYes
Transcribing recorded sessions and voice notesThe audio, for transcription; deleted afterYes
Drafting notes, summaries and insights for your reviewTranscript text with names stripped; nothing is retained or used for trainingYes
Card paymentsAn invoice number and an amount — never a service or a diagnosisNot needed: no PHI
Showing your sessions in your own calendar (optional)Initials, time and location onlyNot needed: no PHI

We name each vendor, and share the signed agreements, once a mutual NDA is in place — which is the normal footing for a diligence review and the one we would ask for in your position. Write to security@practicedocket.com and we will send the list, the BAAs and anything else your review needs.

3. What the AI is allowed to do

4. Who can get in

5. What leaves the platform

Protected health information stays inside. Appointment emails and texts say when and where, not why. Calendar events carry initials. Payment descriptions carry an invoice number. Video meeting titles say "Telehealth session". This is a rule in the code, with tests that fail if anyone breaks it.

6. Audit trail

Every read and write of a client's record is logged with who, what and when, and the log is visible to the practice on the client's page and under Activity. Logs are kept even after a record is deleted, as the law requires.

7. Your data is yours

A practice can export its records and leave. A client's complete record can be produced on request. Cancelling an account does not delete the records the law says a practice must keep; we hold them for the practice, encrypted, for the retention period the practice sets, and then delete them.

8. If something goes wrong

We will tell the affected practice without unreasonable delay, and in every case within the time HIPAA requires, with what happened, what was involved, and what we did. Practices are covered by our Business Associate Agreement, which you sign when you create your practice.

9. What we are working towards

Honest about the gaps: we do not yet hold a SOC 2 report. Annual third-party penetration testing and a formal risk analysis are on the plan for the coming year, ahead of the updated HIPAA Security Rule. This page will say when they are done.

10. Questions

Write to security@practicedocket.com. If you have found a vulnerability, tell us there first and we will take it seriously and thank you for it.