HIPAA Compliance

Last updated: March 18, 2026

1. Overview

Genogram Pro is designed for mental health professionals, social workers, and clinical practitioners who work with sensitive family data. We take the security and privacy of Protected Health Information (PHI) seriously and have built our architecture with healthcare compliance in mind.

This page documents our technical safeguards, security controls, and compliance posture relevant to the Health Insurance Portability and Accountability Act (HIPAA).

2. Zero-Knowledge Encryption

Genogram Pro uses a zero-knowledge encryption architecture. All genogram data is end-to-end encrypted before it leaves your device, and our servers never have access to your decrypted data.

  • Algorithm: AES-GCM 256-bit encryption
  • Key derivation: PBKDF2 with SHA-256 and 100,000 iterations
  • Two-layer encryption: Your password derives a master key, which in turn encrypts all genogram data. The master key is never transmitted to our servers.
  • Device keys: Trusted devices store a non-extractable encryption key in the browser's secure storage (IndexedDB via WebCrypto API), enabling passwordless unlock without compromising security.

Even in the event of a server breach, your data remains protected — the encrypted blobs stored on our servers are useless without your password or trusted device key.

3. Data Handling

  • Encryption at rest: All genogram data, templates, and shared content is stored as encrypted blobs on our servers.
  • Encryption in transit: All data is transmitted over HTTPS/TLS. Additionally, data is already encrypted before transmission due to our end-to-end encryption model.
  • No PHI in URLs: Genogram identifiers in URLs are random tokens (nanoid) that contain no personally identifiable information.
  • Automatic data purge: Soft-deleted records are permanently removed from our systems after 30 days, in accordance with our privacy policy.

4. Access Controls

  • Authentication: Email/password authentication with optional OAuth (Google, GitHub). All accounts require email verification.
  • Row-level isolation: Database queries enforce user-level filtering, ensuring users can only access their own data.
  • Device trust management: Users can review and revoke trusted devices at any time. Each device has its own unique encryption key.
  • Session-scoped access: The master encryption key is stored in session storage and is automatically cleared when the browser tab is closed, requiring re-authentication to access data.

5. Analytics Privacy

We use PostHog for product analytics, with the following privacy controls:

  • Opt-in only: Analytics tracking is disabled by default and only enabled after explicit user consent through our cookie banner.
  • PII masking: All input fields are masked in session recordings. Text displays containing names, dates, and other sensitive information are tagged to prevent capture.
  • EU-hosted: Our PostHog instance is hosted in the European Union.

6. Security Controls Summary

ControlStatus
Encryption at rest (AES-GCM 256-bit E2E)Implemented
Encryption in transit (HTTPS + E2E)Implemented
Access controls (row-level user isolation)Implemented
Authentication (OAuth + password + email verification)Implemented
PHI-free URLsImplemented
Session recording PII maskingImplemented
Opt-in analytics onlyImplemented
Session-scoped encryption keyImplemented
Automatic data purge (30-day retention)Implemented

Addressable Controls

The following HIPAA Security Rule specifications are classified as "addressable" rather than "required." We have evaluated each and documented our rationale:

  • Automatic logoff (§164.312(a)(2)(iii)): The master encryption key is stored in session storage and is automatically cleared when the browser tab is closed. Trusted device keys are stored in the browser's secure IndexedDB and require explicit device trust setup. This provides equivalent protection to an inactivity timeout.
  • Audit controls (§164.312(b)): Our zero-knowledge architecture means the server never has access to decrypted PHI. Authentication events are logged by our auth system. Full PHI access logging is not applicable in a zero-knowledge system where the server cannot access the data it stores.

7. Shared Responsibility

What we provide

  • End-to-end encryption for all genogram data
  • Secure infrastructure with encrypted storage and transmission
  • Access controls and user isolation
  • Privacy-preserving analytics
  • Automatic data purge for deleted records
  • Regular security updates and monitoring

What you are responsible for

  • Choosing a strong master password and keeping it secure
  • Managing trusted device access and revoking devices when needed
  • Your own organization's HIPAA compliance obligations and policies
  • Staff training on proper use of digital tools with PHI
  • Ensuring genogram names do not include patient-identifying information (genogram names are not encrypted)
  • Closing the browser tab when stepping away from your device

8. Business Associate Agreement

A Business Associate Agreement (BAA) is coming soon. If you have questions about using Genogram Pro in a HIPAA-covered context, please contact us at [email protected].

9. Contact

For questions about our HIPAA compliance posture or security practices, please contact us at [email protected].