What the software enforces
Unique access and minimum necessary
Shared ASL authentication with required multi-factor sign-in — authenticator app, or one-time codes by email or text message — isolated practice organizations, named workforce accounts, role-scoped records, prompt access disabling, and time-limited practice-approved support access.
Tamper-evident activity records
Security-relevant events are recorded in a keyed integrity chain. Authorized reviewers can verify continuity and record formal activity and workforce-access reviews.
Protected data and recovery
Selected sensitive fields are encrypted at rest. Daily database snapshots are encrypted with a separate key, restored into a temporary database, integrity checked, and retained on a controlled schedule.
Secure web sessions
TLS at the public edge, exact-origin checks for changes, restrictive browser security headers, no third-party trackers in the protected workspace, no-store API responses, and automatic idle sign-out.
Individual rights and disclosures
Practices can track access, amendment, accounting, restriction, and confidential-communication requests, produce audited record exports, and document the legal basis and minimum-necessary scope of disclosures.
Clinical record integrity
Signed notes are never silently overwritten. Amendments create a separately authored and signed record linked to the preserved original.
Incident and breach workflow
Authorized reviewers can record, contain, assess, and resolve security incidents. Suspected or confirmed breaches remain visibly queued for the organization’s notification procedure; the platform does not make the legal determination automatically.
Evidence-gated activation
Required readiness controls cannot be marked complete without a non-sensitive evidence reference. Practice and platform security officers must provide distinct attestations, and the audit integrity check must pass before activation can be considered.
What software cannot complete for a practice
HIPAA compliance depends on how a covered entity and its business associates operate, not merely which application they buy. Before any live deployment, the parties must determine their roles, execute applicable Business Associate Agreements, complete and maintain a security risk analysis and risk-management plan, approve policies, train the workforce, test incident and recovery procedures, configure retention, review subcontractors, and perform qualified privacy, security, clinical, and legal acceptance.
ASL Therapy therefore uses the term HIPAA-ready safeguards to describe its design. The current public pilot remains restricted to synthetic demonstration records and is not an authorization to enter protected health information.
Evidence a licensed practice can review
The readiness workspace records control status, non-sensitive evidence references, workforce reviews, privacy requests, disclosure accounting, incidents, audit-chain verification, encrypted-backup manifests, and restore-test results. These records help a practice demonstrate that controls are operating, but they must be reviewed in the context of the practice’s own HIPAA obligations and written policies.