mindora

HIPAA Compliance Notice

Last Updated: April 14, 2026

Current Status (2026): Mindora is being built with HIPAA-aligned architecture (end-to-end encryption, audit logs, MFA, AWS Frankfurt). A formal HIPAA Business Associate Agreement (BAA) framework and SOC 2 Type II certification are on the Q1 2028 roadmap. Until then, US users are advised to use Mindora for non-PHI purposes only (application evaluation, training, feedback). The sections below describe the targeted compliance framework.

1. Our Commitment

Mindora is committed to protecting the confidentiality, integrity, and availability of Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the HITECH Act.

As a clinical management platform for therapists, Mindora processes PHI including clinical notes, session records, and client information.

2. What is Protected Health Information (PHI)?

PHI encompasses any individually identifiable information related to an individual's health condition, provision of healthcare, or payment for healthcare. On the Mindora platform, PHI includes:

  • Clinical and session notes
  • Therapy goals and progress records
  • Mental state assessments
  • Session dates and duration
  • Client contact information (when linked to healthcare services)

3. Security Safeguards

Mindora implements administrative, technical, and physical safeguards to protect PHI:

  • Access controls: Organization-level data isolation; each therapist can only access their own client data.
  • Encryption: HTTPS/TLS in transit, AES-256-GCM encryption at rest for sensitive data. Encryption keys are versioned and rotated periodically (key rotation).
  • Authentication: Multi-factor authentication (MFA/TOTP), automatic session locking, and brute-force protection. Login attempts are rate-limited (5 per 15 minutes).
  • Content security: HTTP security headers (Helmet.js) protect against common web vulnerabilities. Clinical notes and blog content are sanitized server-side to prevent XSS attacks.
  • Audit trails: All data access and modifications are logged with user identity, IP address, and timestamps (365-day retention).
  • Payment security: Webhook notifications are secured with cryptographic signature verification and replay attack protection.
  • Physical security: Data is hosted on AWS cloud infrastructure (EU region — Frankfurt).

For a comprehensive overview of our security practices, please visit our Security page.

4. Business Associate Agreements (BAA)

Mindora enters into appropriate Business Associate Agreements with third-party service providers that have access to PHI. These providers include cloud storage, email delivery, and payment processing services.

5. Breach Notification

In accordance with the HIPAA Breach Notification Rule:

  • Individuals affected by a breach of unsecured PHI will be notified within 60 days of discovery.
  • Breaches affecting more than 500 individuals will be reported to the U.S. Department of Health and Human Services (HHS).
  • Breach notifications will include a description of the breach, types of data affected, steps taken, and contact information.

6. Your Rights

Under HIPAA, you have the right to:

  • Access your PHI
  • Request amendments to your PHI
  • Request restrictions on certain uses and disclosures of your PHI
  • Request an accounting of disclosures of your PHI
  • Receive a copy of your PHI in electronic format

7. Minimum Necessary Standard

Mindora applies the minimum necessary standard when using or disclosing PHI. We limit access to only the PHI that is necessary for the intended purpose, through organization-level data isolation and role-based access controls.

8. Contact

For HIPAA compliance questions:
Email: support@usemindora.com
Website: usemindora.com