RITAJA PRACTICE

Trust & security

A plain-language overview for clinicians and practice owners. Ritaja Practice provides secure software; your clinic remains responsible for professional and legal obligations in your country.

The short answers

Will you sign a BAA?
Yes — before you store any real patient information. Details →
Can other practices see my data?
No. Each practice has its own secure, separate space. Details →
Does the AI train on my patients?
No — that is a contractual term, and the feature is off until you turn it on. Details →
Who on my team can open therapy notes?
Only the roles you allow; sensitive content is restricted. Details →

Ritaja Practice is built HIPAA-first for US psychologists and therapy teams — scheduling, clinical notes, billing, secure video, and client portal — and also supports practices in Europe and Asia-Pacific under their own regional rules. It is not for hospital emergency care, crisis hotlines, or use as a medical device.

If you practice in the US, Europe, or Asia-Pacific

Ritaja Practice serves private outpatient clinics around the world. The rules that apply to you depend on where your patients are and where your data is hosted. Your lawyer or compliance advisor can confirm details for your situation—the summary below is meant to orient clinicians, not replace legal advice.

United States

For HIPAA-covered psychology and psychiatry practices: Ritaja Practice supports the technical side; your practice stays responsible for policies, training, and patient rights.

  • Sign a Business Associate Agreement (BAA) with Ritaja Systems before storing real patient information in production
  • Each staff member has their own login with access limited to their role
  • Connections to Ritaja Practice are encrypted (TLS), the same standard used for secure banking websites
  • Optional two-step verification (authenticator app) for staff accounts
BAA overview

Europe (UK & EEA)

Your clinic decides why and how patient data is used (privacy notices, consent, retention). Ritaja Practice stores and runs the software only on your instructions—we do not make those decisions for you.

  • A Data Processing Agreement (DPA) is signed when your practice is activated
  • You remain responsible for patient privacy notices, lawful basis for care, and responding to access or deletion requests
  • Ritaja Practice provides a list of trusted service providers (subprocessors) in your agreement
  • If patients are in the UK or EU, work with your advisor on cross-border data rules
DPA overview

Asia-Pacific

Privacy rules differ by country. Ritaja Practice offers the same security foundation everywhere; your practice aligns with local law.

  • Australia: follow the Australian Privacy Principles (APPs) for how you collect and share information
  • Singapore and other PDPA countries: follow the Personal Data Protection Act (PDPA) for consent and breach reporting where it applies
  • Your data is stored in an encrypted database, with encrypted connections and protected passwords
  • Where data is stored and which vendors are used are spelled out in your service agreement
  • Professional licensing, consent forms, and local breach rules stay with your clinic
DPA overview

Agreements with Ritaja Practice

Before you store real patient information in production, your practice signs the right agreement for your region. Ritaja Practice is not a government certifier—we provide tools; you maintain your compliance program.

United States: Business Associate Agreement (BAA) for HIPAA-covered information. United Kingdom & European Economic Area: Data Processing Agreement (DPA). Both are provided when your practice is activated.

Your clinic's data stays separate

Other practices on Ritaja Practice cannot see your patients, notes, or billing.

  • Each practice has its own secure space in the system.
  • The software blocks access across practices by design.
  • Staff sign in with a practice code so logins belong to your clinic only.

Who can see what

Access follows job role—the front desk does not open full therapy notes unless you allow it.

  • Administrators, clinicians, and reception staff each have different permissions.
  • Sensitive areas (e.g. psychotherapy note content) are restricted by role.
  • New practices are enrolled with two-step verification required for staff accounts. Administrators can adjust this under Settings → Practice.
  • Accounts lock after too many failed sign-in attempts.

Activity records

Important actions are logged so you can review who accessed or changed information.

  • A permanent-style log tracks sensitive access and changes (audit trail).
  • Staff and client portal sign-ins, forms, and messaging leave a record.
  • Old log entries can be removed on a schedule you configure.
  • If Ritaja Practice support signs in to help you (break-glass), it is time-limited, logged, and shown clearly on screen.

Passwords & encryption

Standard protections used by serious health software.

  • All traffic between your browser and Ritaja Practice is encrypted (the padlock you see in your browser).
  • Passwords are one-way hashed using an industry-standard algorithm — we never store readable passwords.
  • Data is held in an encrypted database on a secure cloud provider (region defined in your service agreement), protected at rest.

Session timeouts

How long users stay signed in and what ends a session early.

  • Staff sessions end after 50 minutes of inactivity for psychologists and talk-therapy clinicians, 40 minutes for psychiatrists, or 15 minutes for other staff — or after an 8-hour maximum, whichever comes first. A live video visit or an open clinical note keeps the session open while you work.
  • Only one active staff login per user — signing in elsewhere ends the previous session.
  • Client portal sessions expire after four hours.
  • Login endpoints are rate-limited to reduce brute-force attempts.

Hosting, backups & availability

Where your data lives and how it is protected against loss.

  • Application and databases run on a secure cloud provider (region defined in your service agreement).
  • All traffic between your browser and Ritaja Practice is encrypted.
  • Data is encrypted both in transit and at rest.
  • Each clinic’s data is isolated at multiple layers, so one practice can never see another’s records.

Backups

  • Backups are automated and managed by our hosting provider.
  • Restore procedures are tested as part of deployment operations — contact us for your deployment’s recovery objectives.
  • If you cancel or are suspended, we keep clinical records for 90 days so you can export or request a copy (see the BAA). After that window we return or destroy PHI where feasible.

Log retention

How long activity records are kept in the system.

  • Staff and portal activity logs are retained for a configurable period (default: one year) and can be purged on schedule.
  • Immutable audit trail rows are append-only for accountability investigations.
  • Clinical records follow your clinic’s policies; soft-deleted chart items remain recoverable for a limited window before permanent removal.

Security incidents & breach notification

How to report a concern and what happens if Ritaja Practice discovers a breach.

  • Ritaja Practice will notify affected customers without unreasonable delay when we confirm a breach of unsecured PHI in systems we control, consistent with our Business Associate Agreement and applicable law.
  • Report suspected security issues to our security contact (see Contact below). Include your practice name and a description of what you observed.
  • Your clinic remains responsible for workforce training, device security, and notifying patients when your practice experiences a reportable breach.
  • Security reports: [email protected]

Client portal & video visits

For scheduled outpatient care—not for emergencies. Patients in crisis should call your clinic or local emergency services.

  • Clients can book and message through the portal; bot protection may be enabled on booking.
  • Video visits use private rooms with links that expire—usage is billed separately from your main plan.
  • Recording is off by default. Ritaja Practice does not turn on session recording for you. Optional session transcription (Wave 2+) requires client portal consent before any audio is transcribed during telehealth; raw audio is discarded after transcription.
  • Before going live with video, confirm where video data is hosted and that agreements cover telehealth.

Insurance billing & ERA

Built-in claim workflows for US and EU practices — not outsourced revenue-cycle management.

  • Ritaja Practice includes patient insurance policies, professional claims (837P where enabled), and electronic remittance (ERA) posting tools.
  • Clearinghouse connectivity (e.g. Stedi) is configured per deployment. Your practice enrolls with payers and remains responsible for claim accuracy, timely filing, and appeals.
  • Ritaja Practice does not guarantee payment, adjudication outcomes, or payer enrollment. We provide software — not a billing agency or credentialing service.
  • Insurance claim and ERA features are region-gated. Practices outside supported regions use cash/self-pay billing and superbills as appropriate.

ePrescribing (optional)

Medication workflows in the chart; live e-prescribing requires a separate certified partner.

  • Ritaja Practice tracks medications, allergies, and med-management notes in the patient chart. Electronic prescribing to pharmacies is optional and off until your practice enables it.
  • US practices typically connect through an e-prescribing partner, with per-prescriber vendor fees billed separately from your Ritaja Practice seat fee.
  • Prescribers need valid credentials (NPI, state license, DEA where applicable) and must complete partner identity proofing for controlled substances (EPCS) where required.
  • Outside the US, Ritaja Practice may offer printable or exportable prescriptions; live pharmacy routing depends on local regulations and available partners.

Optional writing help (AI)

Only if your practice turns it on—never required for care.

Staff may use built-in AI writing assistance to polish messages or similar tasks. Your practice opts in after the right agreements are in place. We log that a request happened, not the full text of your clinical notes.

  • Covered by our Business Associate Agreement with Microsoft, and off until your practice has signed a BAA with us and an administrator turns it on — no AI request is permitted before both are true.
  • Your text is not used to train any AI model — this is a contractual term of the service, not just a product setting we chose.
  • Opt-in per practice, and off by default — a practice administrator must explicitly enable it.

Services we may use

Depending on how your practice is deployed, Ritaja Practice may rely on the providers below. Your service agreement lists the subprocessors that apply to you.

Subprocessors that may process clinic or client data depending on deployment configuration
ProviderPurposeWhat they may handle
Cloud hostingApplication hosting, database, and backupsAll clinic and patient data stored in your deployed region

Our hosting provider offers a BAA for covered services when configured for HIPAA workloads.

Email deliveryTransactional email (activation, portal verification, notifications)Email addresses, message content you send via the platform
Video telehealthSecure video visits between clinician and patientVideo session connection details; video/audio per your setup

Your practice confirms agreements cover telehealth if required.

Microsoft Azure OpenAIOptional AI writing assist and clinical documentation drafting (when your practice enables it)Clinical text submitted for that task only, with identifying details removed first. Microsoft’s Azure OpenAI service terms provide that prompts are not retained for model training.

Runs inside our own Azure tenant under a Microsoft Business Associate Agreement — not the public OpenAI API and not a third-party AI vendor. No client or clinician name, date of birth, phone number, email or address is sent to the model in any AI feature: chart assistants and note drafters carry no identifying fields, report drafting substitutes placeholders that are restored afterwards, group notes are pseudonymised, and free-text note excerpts pass through a PHI scrubber first. Our AI request logs record token counts only, never prompt or completion text. Opt-in; requires BAA on file and practice administrator enablement.

Microsoft Azure Speech (optional)Optional clinician dictation — speech-to-text for the clinician composing a noteThe clinician’s own dictated audio; no client audio is captured. Audio is discarded once text is returned.

Same Azure tenant and Business Associate Agreement as above — no third-party scribe or transcription vendor. Only the clinician speaks; sessions are not recorded and clients are not captured, so no client recording consent arises. The clinician reviews and edits the text before signing any note.

E-prescribing partner (US, optional)Optional US e-prescribing when platform and clinic enable eRx add-onPrescriber credentials, patient demographics, allergies, medication orders (via partner UI)

Enabled per clinic; requires prescriber identity proofing (EPCS) through the partner.

Payment processor (not currently in use)Card payment processing for optional patient-portal premium subscriptions. Built but not enabled for any clinic — no card payments are processed today.If enabled: cardholder payment details entered directly with the processor — never sent to or stored by Ritaja Practice — plus billing name and email. Nothing is shared while the integration is off.

We will confirm a Business Associate Agreement is in place with the processor before enabling it for any clinic handling PHI.

Your practice's role

Software supports your program—it does not replace policies, training, or professional judgment.

  • Give each team member their own login—never share passwords.
  • Keep two-step verification required for clinicians and administrators in production.
  • Train staff on minimum necessary access and securing devices.
  • Export records you must keep before closing an account.

Contact

Related compliance guides

All guides →

← Plans & pricing · Trust center · BAA · DPA