Security & compliance
What HIPAA compliance means here.
LactaRoute holds the records of mothers and babies. This page says how they are protected, and what stays in your hands.
No one certifies HIPAA compliance, so we sign a Business Associate Agreement.
Everything that handles patient data is under a signed BAA and HIPAA compliant, so the BAA your practice needs is in place.
The BAA is part of every account. It binds us to use patient information only to run your practice’s services, to keep HIPAA Security Rule safeguards, and to return or destroy your records when you leave.
How patient data is protected
Encrypted at rest
Records, files and recordings are encrypted with AES-256. Credentials you give us, such as payment keys, are encrypted again on their own.
Encrypted in transit
Everything between a browser or the iPhone app and LactaRoute travels encrypted, over TLS 1.2 or newer.
Idle sign-out
Set per practice, from five minutes to a day (six hours unless you change it). A warning comes first; on sign-out, offline copies on that device are cleared.
Access follows role
Each person on your team sees what their role allows, and nothing more.
Sub-processors
The outside services we rely on fall into these categories: hosting and data storage, transcription, email and text delivery, payment processing, and customer support tools. Each one that handles patient data does so under a signed BAA. A current list of sub-processors is available to customers on request, and we tell customers before it changes.
Every access written down
Each view, edit, export, deletion and share of a record is logged with who, when, from which address and device, and whether it was allowed. Refused attempts are logged too. The audit log sits in your compliance dashboard, on every plan.
GDPR · PIPEDA
Your clients’ privacy rights, built in
Self-service, from the compliance dashboard. Families with full portal access can ask for deletion or a freeze themselves; you approve or decline. The record of processing activities exports in one click, and retention periods are yours to set, with expired records purged weekly.
- Export
- A complete, portable copy of a client’s record.
- Rectify
- Correct what is wrong, with the change kept on record.
- Freeze
- Restrict processing of a record, and lift the restriction later.
- Delete
- Erasure requests, approved or declined by you, with the outcome kept.
- Consent
- Per purpose (treatment, communication, marketing, analytics, data sharing), with the policy version recorded and withdrawal in one step.
If something goes wrong
If unsecured patient information is breached, we tell you without unreasonable delay, and never later than 60 days after we discover it.
We name each person affected, as far as we know, give you what you need for your own notices, and work with you under New Jersey’s breach law. Your compliance dashboard keeps a breach log of your own: what happened, its scope, what was contained, and whether regulators and individuals have been notified.
What stays in your hands
Your own accounts
When you connect an account of your own, LactaRoute sends it only what the connection needs, at your direction, and your agreement with that service governs it.
- Spruce Health for texting families
- Google Calendar for keeping your own appointments unbookable
- and any other account you choose to connect, such as your clearinghouse or your own fax service
Your own settings
The controls that decide how cautious your practice is.
- Idle timeout from five minutes to a day
- Roles for who on your team sees what
- Recording consent where the scribe looks for it
- AI features off for the whole practice with one switch
Read the legal documents
- Business Associate Agreement What we promise about patient data, in writing, signed with every account.
- Privacy policy What we collect, why, and how long each kind of record is kept.
- Notice of privacy practices How health information may be used and shared, and the rights it carries.
- Terms of service The agreement your account runs under.
- Accessibility Our accessibility commitment, and how to tell us where we fall short.
Questions
Is LactaRoute HIPAA compliant?
Yes. Everything that handles patient data is under a signed Business Associate Agreement and HIPAA compliant, so the BAA your practice needs is in place. Data is encrypted at rest and in transit, every access is logged, and idle sessions sign out on a window you set. Read the BAA.
Is LactaRoute SOC 2 certified?
No. LactaRoute runs on SOC 2 Type II audited infrastructure; that audit covers the hosting, not LactaRoute itself.
Is scribe audio kept?
The recording is used to make the transcript and then erased. The transcript stays with the visit. More on how the AI scribe handles a visit.
Can families exercise their own rights?
Yes. A family with full access to their portal can ask for deletion or a freeze of their record from there, and you approve or decline it.
What happens to our records if we leave?
You can export your practice’s records first. Under the BAA, records are then returned or destroyed.
Anything this page leaves out, ask us.
Write to hello@lactaroute.com, or see what each LactaRoute plan includes.
