HIPAA Notice
Last updated: July 8, 2026
1. Our Role as a Business Associate
TheraJunction provides software—not direct healthcare—to clinicians and practices that are typically "covered entities" under the Health Insurance Portability and Accountability Act (HIPAA). Because the Service may create, receive, maintain, or transmit protected health information ("PHI") on behalf of these customers, TheraJunction acts as a Business Associate. We enter into a Business Associate Agreement (BAA) with each covered-entity customer, which governs how we handle PHI.
2. How This Notice Relates to You
If you are a covered entity or a clinician customer, this notice summarizes how we handle PHI as your business associate under our BAA.
3. Protected Health Information We Create, Receive, Maintain & Transmit
On behalf of our customers, the Service may process PHI such as:
- clinical notes, transcriptions, and AI-generated documentation;
- scheduling and appointment information;
- secure messages and communications;
- telehealth session data; and
- related practice and billing information that identifies individuals.
4. How We May Use and Disclose PHI
We use and disclose PHI only as permitted or required by HIPAA and our Business Associate Agreement, including to:
- provide and support the Service on behalf of the covered entity;
- perform treatment, payment, and healthcare-operations functions as specified by the customer;
- comply with legal obligations; and
- report as required by law, including breaches and certain audits or investigations.
5. Uses Requiring Authorization & What We Do Not Do
Certain uses and disclosures require patient authorization. We do not:
- use or disclose PHI for marketing;
- sell PHI; or
- use or disclose PHI in a manner not permitted by the BAA or HIPAA.
We may use or disclose de-identified or aggregated data that is no longer PHI in accordance with HIPAA.
6. Safeguards We Use
We implement administrative, physical, and technical safeguards designed to protect PHI, including:
- Encryption: PHI is encrypted in transit and at rest.
- Access controls: access is limited to authorized personnel on a need-to-know basis.
- Audit logging: we log relevant activity to support monitoring and investigations.
- Workforce training: personnel with potential access to PHI receive appropriate training.
- Subcontractor agreements: vendors that may access PHI are bound by Business Associate Agreements.
7. Subcontractors
We engage service providers and subprocessors to help deliver the Service (for example, hosting and infrastructure providers). Where a subprocessor may create, receive, maintain, or transmit PHI, we require written assurances—typically a BAA—committing them to safeguard PHI consistent with HIPAA.
8. Minimum Necessary
We apply the "minimum necessary" standard to our internal access and disclosures of PHI, limiting use and disclosure to the least amount needed to accomplish the intended purpose, consistent with HIPAA.
9. Breach Notification
If we become aware of a breach of unsecured PHI affecting a covered entity's data, we will notify the covered entity in accordance with the BAA and applicable HIPAA breach-notification requirements so the covered entity can fulfill its own notification obligations.
10. Your Rights & How to Exercise Them
Individual HIPAA rights—such as access to records, amendments, an accounting of disclosures, and requests for restrictions—are generally exercised through the covered entity (your provider). TheraJunction cooperates with covered-entity customers to help them respond to such requests as required by our BAA.
11. Changes to This Notice
We may update this HIPAA Notice from time to time. We will indicate the "Last updated" date above and provide notice of material changes through the Service or by other reasonable means.
12. Complaints
Covered-entity customers may submit complaints about our HIPAA practices to us at contact@therajunction.com. You also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against anyone for filing a complaint in good faith.
13. Contact
For questions about this notice or to request a Business Associate Agreement, contact us at contact@therajunction.com. See also our Privacy Policy and Terms of Service.
14. Disclaimer
This notice is a general summary of how TheraJunction handles protected health information as a business associate and is not legal advice. Our specific obligations are set out in the Business Associate Agreement with each covered-entity customer and in applicable federal and state law. In the event of any conflict, the BAA and applicable law control.