Skip to content

Trust

HIPAA & Business Associate Agreement

Cadence handles protected health information (PHI) on behalf of the clinics that use it. Safeguarding that data is the foundation of the product, not a setting you turn on.

Last updated September 2, 2026

Our role

When your organization uses Cadence to capture, document, and bill for care, the client information you enter is PHI and your organization is the covered entity. Cadence ABA, Inc. acts as your Business Associate, processing that PHI only to provide the service and only under a Business Associate Agreement (BAA).

How we safeguard PHI

  • Encryption in transit. All traffic to and from Cadence is served over TLS.
  • Encryption at rest. Data is stored in an encrypted database, and the most sensitive PHI identifiers are additionally protected with field-level AES-256-GCM encryption so they are never stored in the clear.
  • Role-scoped access. Every account has one of eight roles - organization owner, clinic director, BCBA, BCaBA, RBT, biller, auditor, and caregiver - with permissions scoped to the minimum necessary. RBTs and caregivers see only the clients assigned to them; auditors read across their scope and can change nothing.
  • Multi-factor authentication and single sign-on. Any account can add an authenticator-app (TOTP) second factor. Practice plans can require sign-in through your identity provider over SAML or OIDC.
  • Append-only, tamper-evident audit trail. Every PHI read and write, and every agent proposal and human decision, is written to an append-only log in which each entry is sealed with an HMAC at write time, so any alteration is detectable. On the Practice plan the log exports as CSV or JSON, and the record behind any session can be bundled into a payer-facing audit packet.
  • Human sign-off. The system proposes; a clinician signs. No note or claim is finalized without a human review and a name behind it - see AI accuracy & safety for exactly what the agents can and cannot do.
  • Minimum necessary.Automated agents receive only the data needed for the task in front of them, and model calls carry a de-identified token in place of a client's name.
  • Retention you control.Clinical records are kept under your organization's retention policy - seven years after a client is discharged by default, adjustable in settings. Past that window, the encryption keys for a discharged client's direct identifiers are destroyed while the de-identified record and its audit trail remain; a client under legal hold is never affected.

The Business Associate Agreement

Our standard BAA is available to every organization, on every plan, at no charge. Signing up asks you to acknowledge that PHI is processed only under an executed BAA; request ours before you enter client data and we will countersign it, or send us yours to review. If your compliance team needs a copy first, request a BAA here.

Subprocessors

A small number of vetted vendors help us deliver the service. We have executed a BAA with every subprocessor that can touch PHI:

  • Anthropic - the AI models that draft documentation from captured sessions (BAA in place; API traffic is not used to train models).
  • Deepgram - speech-to-text for voice capture, when enabled (BAA in place).
  • Neon - the encrypted Postgres database (BAA in place).
  • Vercel - application hosting and TLS termination (BAA in place).

Two vendors never receive PHI, so no BAA is required:

  • Stripe - billing. Stripe receives only subscription and usage counts.
  • Resend - transactional email: invitations, password resets, email verification, and the relay for our contact form. It receives staff names and email addresses.

Breach notification

In the event of a breach of unsecured PHI, Cadence will notify affected customers without unreasonable delay and consistent with the HIPAA Breach Notification Rule and the terms of your BAA, so your organization can meet its own notification obligations.

Data ownership, return, and deletion

Your organization owns its data. Any client's complete record can be exported from inside Cadence at any time, and on termination PHI is returned or securely destroyed in accordance with your BAA. To request a full export or deletion, contact us.

A note on scope

Cadence supports your organization's HIPAA compliance with the safeguards above; HIPAA compliance is a shared responsibility. Your organization remains responsible for its own administrative, physical, and technical safeguards, including how staff accounts and credentials are managed within your clinic.