Security & Trust
Built HIPAA-first, not HIPAA-eventually.
Most practice software adds compliance as a page in the footer. Suithera was designed the other way around: the rules below are enforced in code, on every request — and this page tells you exactly what they are.
Effective September 4, 2026 · Su Information Technologies LLC, doing business as Suithera · Security contact support@suithera.com
The guarantees
Six rules the code won't let us break.
Each of these is a mechanism, not a policy — it works the same at 3 AM as it does in a demo.
Clinical content — notes, messages, transcripts, identifiers — is encrypted with AES-256-GCM before it touches the database, and TLS everywhere in between.
Writes, AI calls, and reads of client records land in an append-only audit log. The database itself has no delete path for it — the application connects with a role that cannot bypass the rule.
Each AI workflow — documentation, transcription, recording — requires its own recorded client consent. A denied gate blocks the call and logs the block.
The audit trail records a cryptographic hash of every AI prompt — proof of what ran, without a second copy of clinical text sitting in a log.
No AI output enters a chart, claim, or client message without a clinician's explicit signature. Drafts that never get signed never become records.
Full record export — per client or whole practice — any time, in standard formats. A legal hold blocks deletion outright; scheduled retention stays in report-only until a practice turns it on.
The paperwork
A BAA is the floor, not an upsell.
Every covered-entity practice gets one, on every plan, at no extra charge.
- BAA with every covered-entity practice: executed at registration, at every price. Read it →
- HIPAA-eligible AI only: clinical AI is wired to BAA-covered infrastructure and nothing else, and it stays switched off until that BAA chain is confirmed in writing.
- Minimum necessary: clients are identified by initials at intake; the model sees structure, not a life story.
Honesty policy
What we won't claim.
Security pages love vague superlatives. Here's our line: if it isn't enforced in code or signed on paper, it isn't on this page.
- No "military-grade" anything: we name the exact primitives — AES-256-GCM, TLS, SHA-256 hashes.
- No silent AI: every model call is consent-gated, audited, and visible in your agent activity log.
- Your state's rules are yours, not ours: what we enforce in code is this platform's behaviour — encryption, the audit log, consent gates. It is not the law of your state. Vermont bars session recording outright, retention minimums differ by state and by profession, and several states bar a parent from a minor's record. Suithera does not check any of that for you, so the periods and permissions you set here are yours to reconcile with your board.
- Read the terms yourself: the privacy policy, terms, and BAA are public — no sales call required.
Get started
Trust is a feature. Test it.
Sign in and open the audit log yourself — every action you take will already be in it.
Sign in