Your practice and your region
Ask us about hosting location, access controls, retention, backups, and the agreements that apply to your practice. Requirements differ by region and by how you use the product.
Before you bring client information into PracticeVault, let’s make sure the agreements, settings, and services are right for your practice.
Abyde HIPAA badge2025 · existing company assetThe original 2025 Abyde badge is retained as a dated company asset. Current status and scope should be confirmed with the team. It is not a claim of government certification or certification of every integration.
Ask us about hosting location, access controls, retention, backups, and the agreements that apply to your practice. Requirements differ by region and by how you use the product.
AI is optional in the proposed plan. Before enabling it for clinical information, confirm the specific model, data processing terms, retention settings, and approved use with our team.
Generated notes, translations, and summaries need professional review. AI output should not be treated as a diagnosis or an autonomous clinical decision.
Keep SMS reminders brief and avoid sensitive clinical details. Ask us about consent, opt-outs, sender setup, and delivery in your destination country.
White-glove migration remains free. We’ll agree the data scope and transfer process with you before a move. Please don’t upload client records through this marketing website.
The original badge and existing provider documents are below. Ask us for the current practice-specific agreements, evidence, and scope before bringing in clinical information.
Our existing Terms require a signed PracticeVault BAA before HIPAA-covered information is transmitted. A Microsoft or Google provider document does not replace that agreement. For EU practices, confirm the controller/processor roles, applicable data-processing agreement, subprocessors and international-transfer arrangements before onboarding.
The test product includes configurable PHI inactivity blur and a keyboard shortcut. Encryption, MFA, role permissions, audit logs, tenant isolation, backup recovery and incident response need a current deployment-specific evidence review. A visible setting does not establish that the full security control is operating.
Confirm participant permissions, the exact AI service and model, processing region, logging, training/data-use terms and recording retention. Google’s healthcare guidance requires a covered service and applicable BAA, with restrictions on pre-release offerings. A planned model upgrade is not approval to send clinical data.
SMS is not end-to-end encrypted. Keep clinical details out of reminders and use an approved secure portal for sensitive content. Consent records, withdrawal and suppression must work before launch. Two-way numbers can accept STOP/HELP; an alphanumeric sender cannot receive replies and needs another working opt-out method. Message frequency varies and recipients’ carrier charges may apply.
Arrange the required clinical-record export and retention schedule before closing a practice account. The proposal keeps saved generated records accessible when an AI add-on is cancelled. We still need to reconcile this with the existing Terms and confirm deletion, backups and any legally required retention.
The original Privacy page lists SOC 2 Type II certification. This review has not established a supporting report, audit period or scope. That claim and other historical security assurances must be verified or corrected before publication. The 2025 Abyde asset is not a substitute for that review.
References: HHS cloud/BAA guidance · Google Cloud healthcare guidance · GDPR, including Articles 13, 28 and 44 · Messaging consent policy.
Existing provider documents from the original website, labeled by what they actually cover.
Microsoft HIPAA Business Associate AgreementProvider document. Not a substitute for your agreement with PracticeVault.↗Microsoft Products and Services DPAExisting September 2025 provider document. Confirm the applicable current version.↗PracticeVault privacy policyHow the existing website describes data handling.↗PracticeVault terms of serviceExisting commercial terms; the new pricing proposal needs review.↗SMS consent guidanceOpt-in flows, examples, and messaging information.↗Request current security informationBAA/DPA scope, hosting, retention, access, backups and incident procedures.↗Privacy policy ↗
Terms of service ↗
Request security documentation or a data processing agreement ↗
Existing legal documents have not been rewritten as part of this design preview. Updated commercial terms and a review of clinical-data processing are required before launching the new pricing.