← Back to home

Trust & Security

Spectra Health is built for behavioral health, so protecting patient information isn't an add-on — it's the foundation. Here's how we handle security and privacy.

HIPAA & Business Associate Agreements

Your practice is the Covered Entity; Spectra operates as your Business Associate. We sign a Business Associate Agreement (BAA) with every customer before any protected health information (PHI) is entered, and we maintain administrative, physical, and technical safeguards consistent with the HIPAA Security Rule.

We store less about your patients — by design

Spectra does not store patient names, dates of birth, or Social Security numbers. A screening is identified only by a random case number, plus an optional reference your practice chooses and the patient's age and sex. Practices can enable "de-identified mode," which prevents any patient reference from being entered at all.

Encryption everywhere

All data is encrypted in transit (TLS). PHI is additionally protected with application-layer AES-256 field-level encryption before it is stored, so patient answers, scores, notes, and billing data are encrypted at rest. Encryption keys are held separately from the database.

HIPAA-eligible infrastructure

PHI is stored and processed only on HIPAA-eligible cloud infrastructure covered by a signed BAA. We use vetted subprocessors under written agreement — with BAAs wherever PHI is involved. A current subprocessor list is available on request.

Access control & isolation

Access requires an authenticated provider account. Every record is isolated to your organization — one practice can never see another's data. Administrative functions require elevated authorization.

No patient data sent to AI

Spectra generates its documentation drafts and billing-code rationale using deterministic logic on our own infrastructure. We do not send screening responses or clinical content to any third-party AI or large-language-model service.

Secure patient screening

Patient screening links use single-use, time-limited tokens, and patient-facing endpoints are rate-limited. Patients never create accounts and are not identified to Spectra beyond the optional reference your practice chooses.

Audit logging

Key events are logged for accountability. Our logs are designed to be PHI-safe — they exclude screening answers, patient identifiers, and access tokens.

Breach response

In the event of a security incident involving PHI, we follow the notification obligations set out in our Business Associate Agreement.

A note on scope

Spectra is clinical and billing decision-support software — not medical advice, a diagnosis, or an FDA-cleared device. The treating clinician makes all clinical and billing decisions.

Questions?

For security questions, a copy of our subprocessor list, or to request a BAA, contact support@spectrahealth.co.