Last updated: 27 July 2026

HIPAA and clinical data

If you are a therapist, your practice may have HIPAA duties that Closer Couples cannot satisfy with product design alone. This page is the honest version of where things stand today: what the architecture already does, what remains yours to do, and what is not finished yet. For the product walkthrough, start with For Therapists.

Where we actually are

Closer Couples includes technical safeguards designed for privacy conscious clinical workflows. We are deliberately not saying "HIPAA compliant", because compliance is a property of an arrangement between you, us, and our infrastructure providers. One part of that arrangement is not in place yet:

We would rather lose a signup than have a clinician discover this after putting a client's material into the tool.

Why we can't read your clients' content

This is the part that does most of the work, and it is structural rather than a policy we promise to follow. A couple's answers and messages are encrypted on their own devices with a key derived on those devices. Our servers relay ciphertext. There is no administrator view, no support tool, and no database query that returns a couple's words. Not because we choose not to look, but because the data we hold does not decrypt without a key we never receive.

When a couple shares something with you, it is sealed to your console's device keys specifically. It opens on your device and nowhere else. See how we protect your data for the full model.

The safeguards, in plain terms

What stays your responsibility

A tool cannot be compliant on your behalf, and one that implies otherwise is doing you harm. These remain yours:

Questions we expect

Do you have a signed BAA? Not yet. See above; it is the main thing standing between this page and a plain compliance claim.

Can Closer Couples staff read a session? No. Not with a warrant, not with a support escalation, not by accident. The content leaves the couple's devices already encrypted.

What happens if I lose my laptop? Whoever has it faces your vault passphrase, with repeated attempts slowed deliberately, and nothing readable without it. Your couples' devices are unaffected.

Getting back to work depends on one thing: whether backup was on. With it, you sign in on a new computer, enter the same passphrase, and your workspace returns: couples, notes, and your verified identity. Without it, the records existed only on that machine and are gone; that is the trade the encryption makes, and it is why the backup switch is worth finding before you need it. Either way you are not locked out of practising: a new computer can be verified again from inside the console, checked by an admin as it was the first time, and your existing verification keeps working until they approve.

Is my clients' data used for anything else? No. It is not used to train anything, not sold, and not shared. Usage analytics are off unless a user turns them on, and carry no identifier for a person or a couple even then.

See also: Why Closer Couples · Security · Privacy Policy · Support