AbaAiCheck

HIPAA & Compliance

How We Protect Your Clients’ Data

AbaAiCheck is built for HIPAA-covered ABA agencies and clinicians. Here is how we handle protected health information (PHI) and the documents that cover our relationship with you.

Our Safeguards

Business Associate Agreement

We sign a Business Associate Agreement (BAA) with covered entities. Review it at /baa/ or sign it online.

Encryption

Data travels over TLS (HTTPS) and the records we store, such as patients, authorizations and queued claims, are encrypted at rest on HIPAA-eligible cloud infrastructure.

Access Controls & Audit Log

Role-based access by agency and role, plus a tamper-evident HIPAA audit log of sign-ins, PHI access and changes that agency owners can review and export.

Minimum Necessary

The Chrome extension reads your EHR page only when you run a review or sync, never stores note text in the browser, and sends only the fields each feature needs.

Questions from your compliance team?

We are happy to walk your privacy or security officer through our safeguards and the BAA.

HIPAA compliance is a shared responsibility: your agency remains responsible for its own policies, workforce training and the information it chooses to enter. This page summarizes our safeguards and is not legal advice; the BAA, Terms of Service and Privacy Policy govern.