Your clients trust you with their deepest thoughts.
We don’t take that lightly.
HIPAA-Compliant Architecture
PathwayNotes was built with that in mind.
Client data is encrypted, and access stays limited to the people who should have it.
PathwayNotes is HIPAA-compliant, with a BAA available on every plan.
The AI is there to support the work, not make clinical decisions for you.
It uses the context you provide and what your client shares to help you stay connected to what happened between sessions.
You stay in control.
Your clients stay protected.
And the therapy relationship stays at the center.
Security Features
AES-256 Encryption
Industry-standard encryption at rest and in transit. Client notes are encrypted before they leave your computer.
Role-Based Access
You control who sees what. Clinicians in your practice see only their own clients. Admin controls. Simple and granular.
Audit Logging
Every access to client data is logged. You can review who accessed what, when, and for how long. Total transparency.
Data Retention Controls
You set the rules. Auto-delete after 7 years? Done. Keep forever? Your choice. You control the timeline.
Penetration Testing
We run regular security audits. Third-party penetration testing ensures nothing slips through.
SOC 2 Compliance
Working toward SOC 2 Type II certification. Enterprise-grade compliance for therapist-grade care.
How We Handle Your Data
Where it lives
US-based servers (AWS). Data stays in the US unless you explicitly choose otherwise for compliance reasons.
How it's locked
AES-256 encryption at rest. TLS 1.2+ in transit. Encrypted database. Encrypted backups. No plaintext anywhere.
Who can see it
Access is role-based. Clinicians see only their own clients, while practice admins control access across the team.
When clients leave
You can delete a client's data when needed, or set it to auto-delete after a period you choose.
Business Associate Agreements
If you’re part of a covered entity or HIPAA-regulated organization, you’ll need a Business Associate Agreement (BAA). We have them ready. BAAs are included on all plans.
Security Questions
Yes. PathwayNotes uses US-based AWS infrastructure, and data is kept in the US unless another arrangement is specifically required.
Yes. You can delete a client's data when needed or set it to auto-delete after a period you choose. Some information may still need to be retained where required for security, legal, or compliance purposes.
Access is role-based. Clinicians can see the clients assigned to them, while practice admins manage access across the team. PathwayNotes and its service providers process data only as needed to operate and support the platform.
PathwayNotes does not sell client data. We use trusted service providers where needed to run the platform, subject to our privacy, security, and compliance requirements.
No. PathwayNotes does not use client data to train AI models. Client information is processed only as needed to provide the features you and your clients use.
PathwayNotes maintains incident-response procedures for security events and follows applicable notification requirements, including any obligations under your BAA.