Security & HIPAA Compliance

Your health data security is our top priority. Learn how we protect your Protected Health Information (PHI) with enterprise-grade encryption and HIPAA-aligned best practices.

Encryption at Rest

AES-256 Encryption

Military-grade encryption for all stored data

Encrypted Databases

All health records, symptoms, and personal data encrypted

Secure File Storage

PDF uploads encrypted in cloud storage

Encryption in Transit

TLS 1.3 Protocol

Latest encryption standard for data transmission

HTTPS Everywhere

All connections use secure HTTPS protocol

Secure API Calls

All data exchanges encrypted end-to-end

Access Controls & Authentication

Role-Based Access

  • • Users can only access their own data
  • • Admin access strictly controlled
  • • No shared access by default
  • • Granular permission system

Strong Authentication

  • • Secure password requirements
  • • Email verification
  • • Session management
  • • Automatic logout on inactivity

Audit Logging

  • • All data access logged
  • • Timestamps recorded
  • • User activity tracking
  • • 6-year log retention
Third-Party Service Providers & BAAs

We carefully vet all third-party services and require HIPAA-compliant Business Associate Agreements (BAAs) for any vendor that processes Protected Health Information (PHI).

Supabase (Cloud Infrastructure)

BAA Signed

Purpose: Database hosting, file storage, authentication

Compliance: SOC 2 Type II certified, HIPAA-compliant infrastructure with BAA, AES-256 encryption, automatic backups, 99.9% uptime SLA

Stripe (Payment Processing)

BAA Available

Purpose: Subscription billing, payment processing

Compliance: PCI DSS Level 1, HIPAA BAA available for healthcare businesses, does not store PHI (only payment data)

OpenAI (AI Analysis)

Enterprise BAA

Purpose: Generating personalized health recommendations

Compliance: Enterprise tier with HIPAA BAA for PHI processing, zero data retention policy for API calls, SOC 2 Type II certified

Constant Contact (Email Marketing)

HIPAA Option

Purpose: Newsletter delivery, educational content

Compliance: HIPAA-compliant tier available with BAA, we only send educational content (no PHI in emails), users can opt-out anytime

HIPAA-Aligned Safeguards

Technical Safeguards

  • Unique user identification and authentication
  • Automatic logoff after 30 minutes of inactivity
  • Encryption and decryption of ePHI
  • Audit controls and access logs
  • Integrity controls to prevent data alteration
  • Transmission security with encryption

Administrative Safeguards

  • Security risk assessment and management
  • Privacy and security policies
  • Incident response procedures
  • Contingency planning and disaster recovery
  • Business associate agreements with vendors
  • Evaluation and updates to security measures
Your Privacy Rights

Right to Access

View and download all your health data at any time

Right to Amend

Request corrections to your health records

Right to Restrict

Limit how your information is used or shared

Right to Delete

Request complete deletion of your account and data

Breach Notification Commitment

In the unlikely event of a data breach involving your Protected Health Information:

  • • You will be notified within 60 days as required by HIPAA
  • • Notification will include what happened, what information was affected, and steps to protect yourself
  • • We will work with law enforcement and cybersecurity experts
  • • Credit monitoring or identity theft protection may be offered if appropriate
  • • We will report to the Department of Health and Human Services (HHS) as required
Privacy & Security Contacts

Privacy Officer: Melissa Rose
Email: privacy@sagebrushwellness.com
Security Issues: security@sagebrushwellness.com

For HIPAA compliance questions or to file a privacy complaint, contact us at the addresses above. You also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.

Last Updated: June 2026

© 2026 Sagebrush Wellness, LLC. All rights reserved.