HIPAA Compliant Shield

HIPAA Privacy & Security Policy

How SOLO protects your clients' Protected Health Information (PHI) and keeps your practice compliant.

Last updated: May 2026

Important Notice

SOLO provides technical safeguards to support HIPAA compliance, but compliance is ultimately a shared responsibility. Covered entities must execute a BAA with SOLO and maintain their own administrative and physical safeguards. SOLO does not guarantee full HIPAA compliance without a signed BAA in place.

Our Commitment to HIPAA Compliance

SOLO is designed with HIPAA (Health Insurance Portability and Accountability Act) safeguards in mind. We are committed to protecting the privacy and security of Protected Health Information (PHI) for all clients of wellness professionals using our platform.

Technical Safeguards

  • All data is transmitted over encrypted connections (TLS/HTTPS).
  • Role-based access controls restrict what each user can view and edit.
  • Associate Providers cannot access primary provider client contact information.
  • SOAP Notes can be digitally signed and locked to prevent tampering.
  • Audit logs record all significant access and modification events.

Access Controls & Minimum Necessary Standard

  • Each user only sees data relevant to their role (owner, associate, front desk).
  • Associate Providers are scoped to their own appointments and approved services only.
  • Client last names, emails, and phone numbers are protected from associate-level access.
  • Session tokens expire and require re-authentication.

Audit Trail

  • All access to client records, SOAP notes, payments, and forms is logged.
  • Logs capture the acting user, timestamp, action type, and affected resource.
  • Audit logs are immutable and cannot be edited or deleted by practice users.
  • Practice owners can review their full audit trail in Settings → Audit Log.

Business Associate Agreements (BAA)

A Business Associate Agreement (BAA) is required between SOLO and covered entities (practitioners) who handle PHI. If your practice is subject to HIPAA, please contact us to execute a BAA before using SOLO to store or process any client health information.

Breach Notification

In the unlikely event of a data breach affecting PHI, SOLO will notify affected practice owners within the timeframes required by the HIPAA Breach Notification Rule (typically within 60 days of discovery). We maintain incident response procedures to investigate, contain, and remediate any security incidents promptly.

Contact & Questions

For HIPAA-related inquiries, BAA requests, or to report a privacy concern, please contact our Privacy Officer at: sales@solofrontdesk.com. We take all privacy matters seriously and will respond within 5 business days.