Security
Built for records that matter.
Insight Notes holds electronic protected health information for mental health clients — some of the most sensitive data any software handles. These are the controls that are actually built, and, at the end, the things we do not do.
Four controls, not four promises.
At rest
Encrypted where it matters
Isolation
One practice cannot see another
Access
Least privilege, by role
Accountability
An audit trail that cannot be edited
Psychotherapy notes · §164.508
A psychotherapy note is a different record, and the software has to know that.
HIPAA treats the note a clinician keeps for themselves differently from the chart. It sits outside the ordinary right of access, and disclosing it needs a specific written authorization — not the one that covers treatment, payment and operations. Most practice-management software stores it as another note with a checkbox.
Here it is a separate record with its own table, its own access rules and its own audit trail, and it is never carried along by a query that was asking for the chart.
Authorship
Only the clinician who wrote it
Absence is information
The filter is not even offered
What happens when a record leaves.
An export is a disclosure. Whether it was permitted is a question somebody may have to answer years later, so it is decided in code at the moment it happens rather than by whoever remembers the rule.
Before it runs
The authorization is asserted, not assumed
Notes are separate again
Their own authorization, or a refusal
Somebody reading the audit trail should not thereby read the chart.
What you can hand somebody who asks.
Immutable
The log refuses to be rewritten
Six years
Kept as long as the rule requires
No contents
A reference, never the record
Including this
Reading the log is itself logged
When another system needs to read
An API that can only ever read, and only ever a little.
Insight Notes publishes a read-only FHIR R4 surface, so a system you have an agreement with can read the records you choose to share. Interoperability is usually where a careful security story quietly stops, so this is where the limits are worth stating.
Read-only
There is no write path
Narrow on purpose
Demographics and appointments
Still your rules
Restricted clients are not served
Same trail
Every read is audited
Accounts
Passwords
Two-factor authentication
What we do not claim
Every vendor's security page reads the same until you ask what is missing. Ours is written down internally, so it may as well be written down here.
- Substance-use records
- 42 CFR Part 2 is not handled. It requires stricter consent and separate data handling than we have built.
- GDPR and EU residency
- Not handled. Insight Notes is built for United States practices.
- Clients under eighteen
- Not handled. Consent for a minor varies by state, and the rules are specific enough that guessing is worse than declining.
A practice needs a signed business associate agreement before putting client data into any software, including this one. Get in touch and we will send ours.
Read the parts we would rather not advertise.
The gaps above are the reason the rest of this page is worth believing. Nothing here is a certification we do not hold.