First, in plain English: what HIPAA actually asks of you
HIPAA is the federal law that says you must keep your clients' health information private and secure. If it leaks — even by accident — the consequences are real: investigations, fines, and a serious hit to your reputation.
Most agency owners find it confusing for one simple reason: the law tells you what to protect, not how. It requires “encryption,” “access controls,” and “audit trails,” but leaves you to build them.
That “how” is exactly what APDHQ takes off your plate. The safeguards below aren't features you have to switch on and configure — they're how the platform is built, working from the first day you log in.
How APDHQ protects your data
Six safeguards that run automatically, on every account.
Your agency's data is walled off
No other agency using APDHQ can ever see your consumers, staff, or documents. That separation isn't a setting we hope stays on — it's enforced by the database itself on every single request, so there's no path for one agency's data to reach another.
Everything is encrypted
Information moving between your browser and APDHQ is encrypted end to end (that's the padlock in your address bar), and stored data sits on encrypted infrastructure. Whether it's in motion or at rest, it's unreadable to anyone who isn't authorized.
Only the right people get in
Every person has their own login — never a shared one. Admin and staff roles control who can do what, and anyone can turn on two-factor authentication (a one-time code from their phone) for a second lock on the door. You decide who sees what.
Document access is logged
Every time a consumer or employee document is opened, downloaded, or exported, APDHQ records who did it and when in a tamper-proof audit trail that can't be edited or erased — exactly the record a state reviewer or auditor asks to see.
A private document vault
Uploaded files live in private storage — never on a public web link that could be forwarded or guessed. When someone with permission opens a document, APDHQ grants a short-lived, single-use link that expires in about a minute.
Nothing disappears silently
Documents are versioned and kept, and records aren't wiped out from under you. Your history stays intact and reconstructable — which is what protects you when an audit asks you to prove what happened, and when.
Our AI assistant is held to the same standard
Coworker — the AI built into APDHQ — runs on a leading AI provider we have signed a Business Associate Agreement (BAA) with. That's the specific legal contract HIPAA requires before any outside company is allowed to handle health information. And you always stay in the driver's seat: anything that creates a record, saves a note, or sends a document pauses to ask for your approval first.
HIPAA is a shared responsibility — here's the honest split
No software can make an agency “fully compliant” on its own, and any vendor who promises that isn't being straight with you. We carry the technical load; you own the human side. Together it works.
What APDHQ handles
- Encrypting your data in transit and at rest
- Keeping every agency's data isolated from every other
- Logins, roles, and two-factor authentication
- A tamper-proof audit trail of document access
- Private document storage with expiring access links
- Running the platform on HIPAA-eligible infrastructure
- A signed Business Associate Agreement with our AI provider
- Regular security reviews of the whole platform
What your agency handles
- Choosing strong passwords and turning on two-factor authentication
- Deciding who on your team to invite, and their role
- Removing access when someone leaves
- Training your staff on privacy and your own policies
- Keeping your HIPAA policies and risk assessment up to date
Don't worry — APDHQ makes your side easier too, with built-in 2FA, per-person roles, and audit-ready records.
Where we stand today
A living snapshot of our security posture. We keep it current as our program grows.
- Encryption in transit (HTTPS/TLS)In place
- Encryption at restIn place
- Agency-level data isolationIn place
- Unique logins & role-based accessIn place
- Two-factor authentication (2FA)Available
- Document-access audit trailIn place
- Business Associate Agreement with our AI providerSigned
- Hosted on HIPAA-eligible infrastructureIn place
- Independent, ongoing security reviewsOngoing
Security is never “done”
We don't treat compliance as a one-time checkbox. We run regular, independent, adversarial security reviews of the entire platform — deliberately trying to break it — and fix what they surface. This page reflects our current posture, and we'll keep updating it as we go.
Questions agency owners ask us
Is APDHQ “HIPAA certified”?
There is no official government HIPAA certification — be cautious of any vendor that claims one. What matters is whether a system is built to meet the safeguards HIPAA's Security Rule requires. APDHQ is: encryption, access controls, data isolation, and audit trails are built into the platform, and we have them independently reviewed on an ongoing basis.
Does using APDHQ make my agency automatically HIPAA compliant?
HIPAA compliance is shared. APDHQ handles the technical safeguards — the encryption, access controls, isolation, and audit logging the law expects from your software. Your agency is still responsible for its own side: strong passwords and 2FA, who you give access to, staff training, and your written policies. We give you a compliant foundation to build on.
Where is my data stored, and is it encrypted?
Your data is stored on HIPAA-eligible cloud infrastructure and encrypted both while it travels to and from APDHQ and while it sits at rest. Uploaded documents live in private storage that is never exposed on a public link.
Can the AI assistant see my consumers' information?
Coworker, APDHQ's AI assistant, is powered by a leading AI provider we have signed a Business Associate Agreement (BAA) with — the legal contract HIPAA requires before any vendor can handle health information. You stay in control: actions that create, change, or send anything ask for your confirmation first.
What happens if there's a security incident?
Because document access is logged in a tamper-proof trail and records are retained rather than deleted, we can reconstruct what was accessed and when — which is essential to responding correctly. We also run regular adversarial security reviews specifically to find and fix weaknesses before they become incidents.
How do I know this is real and not just marketing?
This page describes controls that are actually built into the product, and we keep it current as our security program grows. On a demo we're happy to walk your team (or your compliance advisor) through exactly how each safeguard works in your own account.
Keep reading
Want to see the safeguards in your own account?
Book a walkthrough and we'll show you exactly how APDHQ keeps your agency's data secure and audit-ready — bring your compliance advisor if you have one.
APDHQ provides the technical safeguards described above. Full HIPAA compliance is a shared responsibility between the software and your agency's own policies, training, and practices. This page is informational and is not legal advice.