HIPAA & security

HIPAA-secure ABA practice software, built that way from the start

Client records are some of the most sensitive data a practice holds. Nūr Evoke encrypts them, limits who can see them by role, signs people in with multi-factor authentication and logs every view and change.

NurEvoke · Audit log
Audit logToday
TimeRoleActionRecord
10:42 AMAdminViewed client recordClient A.
10:31 AMBCBAUpdated session noteNote · Client B.
10:12 AMBillerExported claimClaim · Client C.
9:58 AMRBTViewed client recordClient D.
9:40 AMBillerViewed authorizationClient C.
9:15 AMBCBAUpdated session noteNote · Client E.
9:02 AMAdminViewed client recordClient B.
Role-based access
AdminFull access
BCBAClinical
RBTAssigned clients
BillerBilling
Read-onlyView only
CaregiverPortal
Every view and change is logged.

How client records are protected

Security is part of how the software works, not a setting added afterwards.

Encrypted at rest and in transit

Records are encrypted in storage with AWS KMS keys and travel over TLS. The database itself only accepts encrypted connections.

HIPAA-eligible hosting

Client data is kept on AWS services that are HIPAA-eligible, under a signed AWS Business Associate Agreement. Google Workspace tools are used under its BAA.

Multi-factor sign-in, no stored passwords

People sign in through AWS Cognito with multi-factor authentication. Passwords are never stored in the Nūr Evoke database.

Role-based access

Admins, BCBAs, RBTs, billers, read-only users and caregivers each see only what their job needs. Billing and insurance details are limited to the roles that handle them.

An audit trail of every view and change

Every view of or change to a client record writes an audit log entry, so you can answer who touched what and when.

Your practice’s data stays separate

Every request is scoped to your organization, so one practice never sees another practice’s records.

Backed-up, protected database

The database is encrypted, backed up and protected against accidental deletion.

How a request is protected

  1. 1

    You sign in

    Sign-in goes through multi-factor authentication. No password is stored in the app’s database.

  2. 2

    Your role decides what you see

    Access is limited to your organization, your role and, for clinicians, the clients assigned to you.

  3. 3

    Data is encrypted

    It travels over TLS and is stored encrypted.

  4. 4

    It is logged

    Every view and change is written to the audit log.

Frequently asked questions

Is Nūr Evoke HIPAA compliant?

Nūr Evoke is built to support HIPAA: encryption, access control, audit logging and HIPAA-eligible hosting under signed BAAs. HIPAA compliance also depends on your practice’s own policies, training and risk assessment.

Can I get a Business Associate Agreement?

Ask us. Contact the team using the details on this page and we will go through it with you.

Can every staff member see every client?

No. Access depends on role and organization, and clinicians see the clients they are assigned to.

Can I see who looked at a record?

Yes. Every view and change to a client record is written to an audit log.

More from Nūr Evoke

See it with your own practice in mind

Request a demo and we will walk you through it.