Skip to content
Insight Notes
Menu

Security

Built for records that matter.

Insight Notes holds electronic protected health information for mental health clients — some of the most sensitive data any software handles. These are the controls that are actually built, and, at the end, the things we do not do.

Four controls, not four promises.

At rest

Encrypted where it matters

Every field holding clinical content is encrypted with its own dedicated key, separate from the application key, so client data can be rotated independently of everything else.

Isolation

One practice cannot see another

Every record carrying client data is scoped to its practice by a global rule, and every action is checked against a policy as well. Two independent mechanisms, because a single missing scope is how one practice sees another's clients.

Access

Least privilege, by role

An owner, a clinician, a front-desk administrator and a biller see different things. A clinician's access can be narrowed to their own caseload, and psychotherapy notes stay readable only to their author — separated from the chart, with their own access rules and their own audit trail.

Accountability

An audit trail that cannot be edited

Reads and changes to client records are recorded permanently — who, what, when. The log refuses to be updated or deleted at the database layer, and it never stores the contents of a record, only a reference to it.

Psychotherapy notes · §164.508

A psychotherapy note is a different record, and the software has to know that.

HIPAA treats the note a clinician keeps for themselves differently from the chart. It sits outside the ordinary right of access, and disclosing it needs a specific written authorization — not the one that covers treatment, payment and operations. Most practice-management software stores it as another note with a checkbox.

Here it is a separate record with its own table, its own access rules and its own audit trail, and it is never carried along by a query that was asking for the chart.

Authorship

Only the clinician who wrote it

The chart timeline's query for these notes is scoped to their author. A supervisor, an owner and a biller are not exceptions — a non-author does not get a filtered view of them, they get no rows.

Absence is information

The filter is not even offered

A biller shown a "psychotherapy note" filter has been told the category is part of the chart they are reading. They can then select it and be told there is nothing — which is a statement about that client either way. So the filter appears only for somebody who has actually authored one on that chart.

What happens when a record leaves.

An export is a disclosure. Whether it was permitted is a question somebody may have to answer years later, so it is decided in code at the moment it happens rather than by whoever remembers the rule.

Before it runs

The authorization is asserted, not assumed

Exporting a client's record checks that the disclosure is authorized before it produces anything. A front desk confirming they have the signed form on file is not the control.

Notes are separate again

Their own authorization, or a refusal

Including psychotherapy notes in an export requires an authorization scoped to those notes specifically. Without one the export refuses out loud rather than quietly leaving them out — and the export records which authorization permitted it, so the answer survives the person who ran it.

Somebody reading the audit trail should not thereby read the chart.

What you can hand somebody who asks.

Immutable

The log refuses to be rewritten

Not "we do not edit it" — an attempt to update or delete an audit entry raises an error in the application itself. A trail that can be tidied is a trail that will be, on the day somebody most wants it tidy.

Six years

Kept as long as the rule requires

Entries are retained for the six years HIPAA asks for, and pruned past it on a schedule rather than accumulating forever — a record kept beyond its purpose is a record that can still be breached.

No contents

A reference, never the record

An entry says who did what to which record, and when. It never copies the clinical content in. An audit log that quotes the note is a second copy of the chart, held somewhere with different access rules.

Including this

Reading the log is itself logged

Opening the audit trail is an event in the audit trail. The role that exists to review what everyone else did takes part in nothing it reviews, so it is the one place where watching has to be watched too.
Account activity
Which kind of event to show

When another system needs to read

An API that can only ever read, and only ever a little.

Insight Notes publishes a read-only FHIR R4 surface, so a system you have an agreement with can read the records you choose to share. Interoperability is usually where a careful security story quietly stops, so this is where the limits are worth stating.

Read-only

There is no write path

Four endpoints, all of them GET. Not a permission that could be widened later — nothing exists that would accept a change, so a compromised token cannot alter a record, only read the few it is allowed.

Narrow on purpose

Demographics and appointments

A person and their appointments, and that is all. No notes, no documents, no measures, no billing. Psychotherapy notes are not merely excluded here; nothing on this surface has ever been able to reach them.

Still your rules

Restricted clients are not served

A client whose record is marked restricted is absent from the API exactly as they are from a bulk export. And a record that is restricted, belongs to another practice, or never existed all answer the same way — so the API cannot be used to find out whether somebody is a client.

Same trail

Every read is audited

A system reading a chart through the API appears in the audit log the way a person opening it does. One token belongs to one practice, it is shown once when it is issued, and revoking it takes effect immediately — revoked tokens stay on the list, so what has had access remains answerable.

Accounts

Passwords

Minimum twelve characters and checked against known breach lists on the way in. No forced monthly rotation and no composition puzzles — both are discredited, and both mainly produce passwords with a number on the end.

Two-factor authentication

Available to every account and recommended in the product — not required. The HIPAA Security Rule requires authentication and does not currently name two-factor; a 2025 proposal would change that, and if it is finalised this becomes something we require rather than something we urge.

What we do not claim

Every vendor's security page reads the same until you ask what is missing. Ours is written down internally, so it may as well be written down here.

Substance-use records
42 CFR Part 2 is not handled. It requires stricter consent and separate data handling than we have built.
GDPR and EU residency
Not handled. Insight Notes is built for United States practices.
Clients under eighteen
Not handled. Consent for a minor varies by state, and the rules are specific enough that guessing is worse than declining.

A practice needs a signed business associate agreement before putting client data into any software, including this one. Get in touch and we will send ours.

Read the parts we would rather not advertise.

The gaps above are the reason the rest of this page is worth believing. Nothing here is a certification we do not hold.