Security & Compliance
Security you don't have to think about.
Your BAA and DPA are signed the moment your clinic activates. Every practice gets its own separate database, encrypted in transit and at rest, with a full audit trail on every record. Set up by a psychologist who understands what is at stake.
Prefer it in plain language? Read the Trust centre.
HIPAA-ready
BAA signed at activation
EU GDPR-ready
DPA signed at activation
UK GDPR-ready
DPA signed at activation
HITECH
Breach notification covered
Data isolation
A separate database per clinic — not a shared one with row filters.
A common pattern in multi-tenant software puts every customer's data in one shared database, separated by row-level permissions — like tenants sharing one building with locked doors between units. Ritaja Practice does not use that pattern. Every clinic gets its own separate database — its own house, not a room in someone else's building.
In technical terms: that common pattern is Row-Level Security (RLS) inside one shared database — a single table holding every clinic's patients, with a filter deciding which rows each clinic is allowed to see. Ritaja Practice does not use that model. Each clinic gets its own isolated database. There is no shared table for a misconfigured filter to leak across, because there is no shared table.
The common approach
Shared database, row-level security
One database, one set of tables, every clinic's records side by side. A policy on each query restricts which rows a given clinic can read or write. This works — until a policy is missing, a new code path forgets to apply it, or a query runs with elevated privileges. When that happens, the failure mode is one clinic seeing another clinic's patients, not a crash.
What Ritaja Practice does
One database per clinic
Every clinic's data lives in its own database, addressed separately at the connection level. A bug in a query cannot return another clinic's rows, because the query never has a connection to another clinic's database in the first place. The isolation is structural, not a filter that has to be remembered and applied correctly on every code path.
What each framework means here
Not badges. The safeguards behind them.
Compliance is ultimately a property of your whole practice, not of any single vendor’s product — so instead of asking you to trust a badge, here is exactly what we do, in each framework’s terms, for you to hold us to.
United States
HIPAA
We act as your Business Associate.
- BAA signed automatically at clinic activation
- PHI encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Full audit trail on every PHI read, write, and delete
- Minimum-necessary access enforced by role
European Union & United Kingdom
GDPR & UK GDPR
We act as your data processor.
- DPA signed automatically at clinic activation
- Data hosted in your region — no cross-border transfer by default
- Documented subprocessors, listed in full below
- Export your data, in full, whenever you ask
United States
HITECH
Breach notification is a duty, not a feature.
- Notification within the HITECH 60-day rule
- Audit log is the evidence trail for any investigation
- Business-associate obligations apply to us directly
- Incident process documented and reviewed
India
India — DPDP Act & IT Rules
Built ahead of a law still being phased in.
- Health records already sensitive personal data under the IT Act, 2011 rules
- Consent, access logging, and data isolation built now — not deferred to a deadline
- DPDP Act, 2023 enacted; main provisions not yet in force as of this writing
- We track the DPDP commencement timeline and will update this page when it changes
Data residency
Your data stays in your region.
Choose where your clinic data is hosted at activation. Data is never transferred between regions without explicit consent and a valid transfer mechanism.
🇺🇸
United States
US-based infrastructure
HIPAA · HITECH
🇪🇺
European Union
EU-based infrastructure
EU GDPR
🇬🇧
United Kingdom
UK-based infrastructure
UK GDPR
🇮🇳
India
APAC-based infrastructure
IT Act rules · DPDP (enacted)
If you leave
Your records are still yours after you cancel.
- Export client demographics, clinical notes, and billing history in standard formats (CSV/PDF) at any time while your account is active.
- If you cancel or are suspended, we keep clinical records for 90 days so you can still export or request a copy — see your BAA for the exact terms.
- After that window, we return or destroy PHI where feasible. We do not hold your patient records hostage to keep you subscribed.
Technical controls
Security built into every layer.
Encryption everywhere
All data encrypted in transit using TLS 1.2+ and at rest using AES-256. Encryption applies to database records, file storage, and backups.
Data isolation per practice
Every clinic's data is logically isolated. No shared tables across practices. One clinic's data can never be accessed by another.
Role-based access control
Staff permissions scoped to their role — clinician, admin, front desk, or owner. No over-provisioned access. Audit trail on every change.
Full audit trail
Every read, write, and delete on clinical records and billing data is logged with timestamp, user, and action. Immutable for compliance reviews.
Secure client portal
Client authentication is separate from staff authentication. Portal access is scoped to the individual client's own records only.
No PHI in URLs or logs
Patient identifiers are never passed in query strings or written to application logs. Error monitoring receives sanitised, non-PHI payloads.
Security testing before every release
Every deploy runs automated dependency and secrets scanning, tenant-isolation fuzzing that checks live responses for PHI leaks, and an OWASP ZAP dynamic scan against the running application — not a one-time audit, a gate that has to pass before code ships.
Messaging & access
Your practice already has a chat app. It should not hold PHI.
Clinics run on Slack, WhatsApp, and SMS — between colleagues and with clients — because the software they bought had nowhere to talk. Every one of those threads is clinical detail sitting outside the record, outside your BAA, and outside any audit trail.
Messaging, inside the system
Pulse is built-in team messaging and the client portal carries client conversations — both under the same BAA, tenant isolation, and audit trail as the chart itself. No separate vendor, no separate login, and no clinical detail leaving for a consumer chat app.
It knows when to stay quiet
Messaging goes silent inside a live session and stays quiet while you are writing a note or preparing for a client. Unread still accrues — nothing is lost, you are simply not interrupted mid-clinical-work.
Two-factor authentication
Time-based one-time codes (TOTP) from any authenticator app, with trusted-device handling and a secret-rotation policy. Available to every staff member, and enforceable across your whole practice.
Clients authenticate into their own portal and can only ever reach their own threads. When a client writes in, the message is routed by topic — billing to your biller, scheduling to your front desk, clinical to their own clinician — so nothing lands in a shared inbox nobody owns.
United States
HIPAA & BAA
Ritaja Practice acts as your Business Associate for all protected health information (PHI) processed through the platform. Your Business Associate Agreement (BAA) is signed automatically when your clinic activates — no paperwork chase.
- BAA signed at clinic activation — not on request
- PHI encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Access limited to authenticated, role-based staff
- Full audit log on every PHI access and change
- Breach notification process per HITECH 60-day rule
- Minimum necessary access enforced across the platform
EU & UK
GDPR & DPA
For clinics in the European Union and United Kingdom, Ritaja Practice acts as your Data Processor. Your Data Processing Agreement (DPA) is signed automatically at activation, covering all personal data processed on behalf of your practice.
- DPA signed at clinic activation for EU and UK clinics
- Data hosted within your chosen region (EU / UK infrastructure)
- Data subject rights supported: access, rectification, erasure
- Lawful basis for processing documented per regulation
- Breach notification within 72 hours per GDPR Article 33
- Subprocessor list maintained and available on request
Breach notification
We notify you. Fast.
HIPAA / HITECH
60 days from discovery
We notify affected clinics and assist in notifying affected individuals and the US Department of Health and Human Services (HHS) within required timelines.
EU GDPR
72 hours to supervisory authority
We notify your clinic within 24 hours of confirmed breach so you can fulfil your 72-hour obligation to your national supervisory authority.
UK GDPR
72 hours to ICO
Same commitment as EU GDPR. We notify your clinic within 24 hours to give you time to report to the Information Commissioner's Office.
Subprocessors
Who processes your data.
Ritaja Practice uses a limited set of sub-processors. All are bound by data processing agreements and assessed for security posture before use. Optional add-ons (AI, video, SMS) only involve their respective sub-processors when those features are enabled by your clinic.
| Provider | Purpose | What they may handle |
|---|---|---|
| Cloud hosting | Application hosting, database, and backups | All clinic and patient data stored in your deployed region Our hosting provider offers a BAA for covered services when configured for HIPAA workloads. |
| Email delivery | Transactional email (activation, portal verification, notifications) | Email addresses, message content you send via the platform |
| Video telehealth | Secure video visits between clinician and patient | Video session connection details; video/audio per your setup Your practice confirms agreements cover telehealth if required. |
| Microsoft Azure OpenAI | Optional AI writing assist and clinical documentation drafting (when your practice enables it) | Clinical text submitted for that task only, with identifying details removed first. Microsoft’s Azure OpenAI service terms provide that prompts are not retained for model training. Runs inside our own Azure tenant under a Microsoft Business Associate Agreement — not the public OpenAI API and not a third-party AI vendor. No client or clinician name, date of birth, phone number, email or address is sent to the model in any AI feature: chart assistants and note drafters carry no identifying fields, report drafting substitutes placeholders that are restored afterwards, group notes are pseudonymised, and free-text note excerpts pass through a PHI scrubber first. Our AI request logs record token counts only, never prompt or completion text. Opt-in; requires BAA on file and practice administrator enablement. |
| Microsoft Azure Speech (optional) | Optional clinician dictation — speech-to-text for the clinician composing a note | The clinician’s own dictated audio; no client audio is captured. Audio is discarded once text is returned. Same Azure tenant and Business Associate Agreement as above — no third-party scribe or transcription vendor. Only the clinician speaks; sessions are not recorded and clients are not captured, so no client recording consent arises. The clinician reviews and edits the text before signing any note. |
| E-prescribing partner (US, optional) | Optional US e-prescribing when platform and clinic enable eRx add-on | Prescriber credentials, patient demographics, allergies, medication orders (via partner UI) Enabled per clinic; requires prescriber identity proofing (EPCS) through the partner. |
| Payment processor (not currently in use) | Card payment processing for optional patient-portal premium subscriptions. Built but not enabled for any clinic — no card payments are processed today. | If enabled: cardholder payment details entered directly with the processor — never sent to or stored by Ritaja Practice — plus billing name and email. Nothing is shared while the integration is off. We will confirm a Business Associate Agreement is in place with the processor before enabling it for any clinic handling PHI. |
Questions about a specific vendor or data flow? Contact us.
Security questions
Talk to our team.
Enterprise buyers, compliance officers, and procurement teams — we are happy to answer specific questions, share our security posture documentation, or arrange a call with our team.
Ready to simplify your practice?
Calendar, notes, billing, payroll, and client portal — in one workspace.
No card required to sign up. Your trial begins when you complete clinic activation. Your bill is your plan rate times your billable clinicians, plus any add-ons you turn on.