Skip to content
Trust starts with clear answers

Your clients’ data.
Your responsibility.
Ours, too.

Before you bring client information into PracticeVault, let’s make sure the agreements, settings, and services are right for your practice.

Existing Abyde Certified HIPAA for Business Associates badge, dated 2025Abyde HIPAA badge2025 · existing company asset
Privacy in the workflowPHI blur in the real product
Agreements, within reachBAA & data processing documentsPeople you can reachDirect access to the founders

The original 2025 Abyde badge is retained as a dated company asset. Current status and scope should be confirmed with the team. It is not a claim of government certification or certification of every integration.

Your practice and your region

Ask us about hosting location, access controls, retention, backups, and the agreements that apply to your practice. Requirements differ by region and by how you use the product.

A deliberate choice about AI

AI is optional in the proposed plan. Before enabling it for clinical information, confirm the specific model, data processing terms, retention settings, and approved use with our team.

Keep the clinician in control

Generated notes, translations, and summaries need professional review. AI output should not be treated as a diagnosis or an autonomous clinical decision.

Careful communication

Keep SMS reminders brief and avoid sensitive clinical details. Ask us about consent, opt-outs, sender setup, and delivery in your destination country.

Help with your migration

White-glove migration remains free. We’ll agree the data scope and transfer process with you before a move. Please don’t upload client records through this marketing website.

Security documentation

The original badge and existing provider documents are below. Ask us for the current practice-specific agreements, evidence, and scope before bringing in clinical information.

Before clinical use

The agreements.
The actual safeguards.

A PracticeVault agreement.

Our existing Terms require a signed PracticeVault BAA before HIPAA-covered information is transmitted. A Microsoft or Google provider document does not replace that agreement. For EU practices, confirm the controller/processor roles, applicable data-processing agreement, subprocessors and international-transfer arrangements before onboarding.

Controls you can inspect.

The test product includes configurable PHI inactivity blur and a keyboard shortcut. Encryption, MFA, role permissions, audit logs, tenant isolation, backup recovery and incident response need a current deployment-specific evidence review. A visible setting does not establish that the full security control is operating.

Recording and AI data handling.

Confirm participant permissions, the exact AI service and model, processing region, logging, training/data-use terms and recording retention. Google’s healthcare guidance requires a covered service and applicable BAA, with restrictions on pre-release offerings. A planned model upgrade is not approval to send clinical data.

SMS consent and safer reminders.

SMS is not end-to-end encrypted. Keep clinical details out of reminders and use an approved secure portal for sensitive content. Consent records, withdrawal and suppression must work before launch. Two-way numbers can accept STOP/HELP; an alphanumeric sender cannot receive replies and needs another working opt-out method. Message frequency varies and recipients’ carrier charges may apply.

Access, export and retention.

Arrange the required clinical-record export and retention schedule before closing a practice account. The proposal keeps saved generated records accessible when an AI add-on is cancelled. We still need to reconcile this with the existing Terms and confirm deletion, backups and any legally required retention.

Evidence before badges.

The original Privacy page lists SOC 2 Type II certification. This review has not established a supporting report, audit period or scope. That claim and other historical security assurances must be verified or corrected before publication. The 2025 Abyde asset is not a substitute for that review.

References: HHS cloud/BAA guidance · Google Cloud healthcare guidance · GDPR, including Articles 13, 28 and 44 · Messaging consent policy.

The document shelf

Read the details.

Existing provider documents from the original website, labeled by what they actually cover.

Microsoft HIPAA Business Associate AgreementProvider document. Not a substitute for your agreement with PracticeVault.Microsoft Products and Services DPAExisting September 2025 provider document. Confirm the applicable current version.PracticeVault privacy policyHow the existing website describes data handling.PracticeVault terms of serviceExisting commercial terms; the new pricing proposal needs review.SMS consent guidanceOpt-in flows, examples, and messaging information.Request current security informationBAA/DPA scope, hosting, retention, access, backups and incident procedures.

Read the policies. Ask the questions.

Privacy policy ↗
Terms of service ↗
Request security documentation or a data processing agreement ↗

Existing legal documents have not been rewritten as part of this design preview. Updated commercial terms and a review of clinical-data processing are required before launching the new pricing.