Trust
HIPAA & Business Associate Agreement
Cadence handles protected health information (PHI) on behalf of the clinics that use it. Safeguarding that data is the foundation of the product, not a setting you turn on.
Last updated June 30, 2026
Our role
When your organization uses Cadence to capture, document, and bill for care, the client information you enter is PHI and your organization is the covered entity. Cadence ABA, Inc. acts as your Business Associate, processing that PHI only to provide the service and only under a signed Business Associate Agreement (BAA).
How we safeguard PHI
- Encryption in transit. All traffic to and from Cadence is served over TLS.
- Encryption at rest. Data is stored in an encrypted database, and the most sensitive PHI identifiers are additionally protected with field-level AES-256-GCM encryption so they are never stored in the clear.
- Role-based access control. RBT, BCBA, biller, and director permissions are scoped to the minimum necessary—the right people see the right record, and nothing more.
- Append-only audit trail. Every PHI read and write, and every agent proposal and human decision, is recorded in an immutable log that can be exported as an audit packet.
- Human sign-off. The system proposes; a qualified clinician signs. No note or claim is finalized without a human review and a name behind it.
- Minimum necessary. Automated agents receive only the data needed for the task in front of them.
Requesting a BAA
We execute a BAA with every organization before any PHI is processed in production. If you need a copy to review with your compliance team, or you are ready to sign, request a BAA here and we will send our standard agreement.
Subprocessors and their BAAs
A small number of vetted vendors help us deliver the service. We have executed a BAA with every subprocessor that can touch PHI:
- Anthropic — the AI models that draft documentation from captured sessions (BAA in place; zero data retention for covered traffic).
- Deepgram — speech-to-text for voice capture, when enabled (BAA in place).
- Neon — the encrypted Postgres database (BAA in place).
- Vercel — application hosting and TLS termination (BAA in place).
- Stripe — billing. Stripe receives only subscription and usage counts, never PHI, so no BAA is required.
Breach notification
In the event of a breach of unsecured PHI, Cadence will notify affected customers without unreasonable delay and consistent with the HIPAA Breach Notification Rule and the terms of your BAA, so your organization can meet its own notification obligations.
Data ownership, return, and deletion
Your organization owns its data. On termination, PHI is returned or securely destroyed in accordance with your BAA. You can request export or deletion at any time by contacting us.
A note on scope
Cadence supports your organization's HIPAA compliance with the safeguards above; HIPAA compliance is a shared responsibility. Your organization remains responsible for its own administrative, physical, and technical safeguards, including how staff accounts and credentials are managed within your clinic.