See a full day run through Vochella, intake to superbill.Book a demo

Trust & Safety

Security & Compliance

Vochella is built from the ground up to protect sensitive health information.

HIPAA
PHIPA
PIPEDA

HIPAA Compliance

Vochella signs a Business Associate Agreement (BAA) with the vendors that store or process clinical data on our behalf. The current list, and what each one handles, is in our BAA. We follow the minimum necessary principle - only the data required for a specific function is ever accessed or transmitted. All protected health information (PHI) is handled according to HIPAA, PHIPA, and PIPEDA requirements.

  • A signed agreement with each vendor that stores or processes clinical data, listed in our BAA
  • Minimum necessary principle enforced at every layer
  • PHI never exposed in logs, error reports, or notifications
  • Workforce training and documented compliance policies

Data Encryption

All data is encrypted both in transit and at rest. API calls are served exclusively over HTTPS with TLS 1.3. Databases use AES-256 encryption at rest. File access (videos, documents) uses time-limited signed URLs that expire automatically.

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for all data at rest
  • Signed URLs with 1-hour automatic expiry
  • Secure token storage using platform-native keychains

Access Control

Row-level security (RLS) policies are enforced at the database level - not in application code. Every query is scoped to the authenticated user. Clinicians can only access their own clients. Clients can only see their own data. Access to receipts, progress reports and exports is logged before the data is returned.

  • Row-level security on every database table
  • Role-based access: clinician, client, admin
  • Audit trail for receipts, reports, and PHI access
  • Session tokens with automatic expiration and refresh

Infrastructure

Vochella is built on Supabase (SOC 2 Type II certified) for database, authentication, storage, and serverless functions. Payments are processed through Stripe (PCI DSS Level 1 compliant). All secrets and API keys are stored in edge functions - never in client code.

  • Supabase: SOC 2 Type II, ISO 27001
  • Stripe: PCI DSS Level 1 certified
  • Edge functions for all server-side secrets
  • No client-side exposure of API keys or credentials

Data Processing & Privacy

When Vochella generates session prep briefs or transcribes a dictated note, clinical data is processed through vendors under a Business Associate Agreement. We apply the minimum necessary standard and strip direct identifiers (such as client names) where technically feasible. All processing runs through server-side edge functions.

  • Direct identifiers stripped before transmission where feasible
  • Covered by a Business Associate Agreement with the vendor, and never used to train models
  • Minimum necessary standard applied to every request
  • Processing via edge functions - never client-side

Your Rights

You own your data. You can export your caseload at any time, and you can request full account and data deletion. If a breach ever involves your data, we notify you without unreasonable delay, and no later than the timeline set out in our BAA.

  • Caseload export at any time
  • Complete account and data deletion on request
  • Breach notification on the timeline in our BAA
  • Transparent privacy policy with no hidden clauses

Our Compliance Commitment

Security and compliance are not afterthoughts - they are foundational to every architectural decision we make. From database schema design to API endpoint access patterns, PHI protection is enforced at every layer of the stack.

Business Associate Agreement

Our BAA & Data Processing Agreement is included with every paid plan and covers HIPAA, PHIPA, and PIPEDA. Read the full agreement or request a signed copy.

Better tools to manage your SLP practice

Spend less time on paperwork and more time on what matters: real progress.