Skip to main content
LactaRoute

Security & compliance

What HIPAA compliance means here.

LactaRoute holds the records of mothers and babies. This page says how they are protected, and what stays in your hands.

No one certifies HIPAA compliance, so we sign a Business Associate Agreement.

Everything that handles patient data is under a signed BAA and HIPAA compliant, so the BAA your practice needs is in place.

The BAA is part of every account. It binds us to use patient information only to run your practice’s services, to keep HIPAA Security Rule safeguards, and to return or destroy your records when you leave.

Read the Business Associate Agreement →

How patient data is protected

Encrypted at rest

Records, files and recordings are encrypted with AES-256. Credentials you give us, such as payment keys, are encrypted again on their own.

Encrypted in transit

Everything between a browser or the iPhone app and LactaRoute travels encrypted, over TLS 1.2 or newer.

Idle sign-out

Set per practice, from five minutes to a day (six hours unless you change it). A warning comes first; on sign-out, offline copies on that device are cleared.

Access follows role

Each person on your team sees what their role allows, and nothing more.

Sub-processors

The outside services we rely on fall into these categories: hosting and data storage, transcription, email and text delivery, payment processing, and customer support tools. Each one that handles patient data does so under a signed BAA. A current list of sub-processors is available to customers on request, and we tell customers before it changes.

Every access written down

Each view, edit, export, deletion and share of a record is logged with who, when, from which address and device, and whether it was allowed. Refused attempts are logged too. The audit log sits in your compliance dashboard, on every plan.

GDPR · PIPEDA

Your clients’ privacy rights, built in

Self-service, from the compliance dashboard. Families with full portal access can ask for deletion or a freeze themselves; you approve or decline. The record of processing activities exports in one click, and retention periods are yours to set, with expired records purged weekly.

Export
A complete, portable copy of a client’s record.
Rectify
Correct what is wrong, with the change kept on record.
Freeze
Restrict processing of a record, and lift the restriction later.
Delete
Erasure requests, approved or declined by you, with the outcome kept.
Consent
Per purpose (treatment, communication, marketing, analytics, data sharing), with the policy version recorded and withdrawal in one step.

If something goes wrong

If unsecured patient information is breached, we tell you without unreasonable delay, and never later than 60 days after we discover it.

We name each person affected, as far as we know, give you what you need for your own notices, and work with you under New Jersey’s breach law. Your compliance dashboard keeps a breach log of your own: what happened, its scope, what was contained, and whether regulators and individuals have been notified.

What stays in your hands

Your own accounts

When you connect an account of your own, LactaRoute sends it only what the connection needs, at your direction, and your agreement with that service governs it.

  • Spruce Health for texting families
  • Google Calendar for keeping your own appointments unbookable
  • and any other account you choose to connect, such as your clearinghouse or your own fax service

Your own settings

The controls that decide how cautious your practice is.

  • Idle timeout from five minutes to a day
  • Roles for who on your team sees what
  • Recording consent where the scribe looks for it
  • AI features off for the whole practice with one switch

Read the legal documents

Questions

Is LactaRoute HIPAA compliant?

Yes. Everything that handles patient data is under a signed Business Associate Agreement and HIPAA compliant, so the BAA your practice needs is in place. Data is encrypted at rest and in transit, every access is logged, and idle sessions sign out on a window you set. Read the BAA.

Is LactaRoute SOC 2 certified?

No. LactaRoute runs on SOC 2 Type II audited infrastructure; that audit covers the hosting, not LactaRoute itself.

Is scribe audio kept?

The recording is used to make the transcript and then erased. The transcript stays with the visit. More on how the AI scribe handles a visit.

Can families exercise their own rights?

Yes. A family with full access to their portal can ask for deletion or a freeze of their record from there, and you approve or decline it.

What happens to our records if we leave?

You can export your practice’s records first. Under the BAA, records are then returned or destroyed.

Anything this page leaves out, ask us.

Write to hello@lactaroute.com, or see what each LactaRoute plan includes.

Start free trial