HIPAA & security
Protected messages deserve a protected channel.
This practice is built for HIPAA-aligned operations: encrypted secure chat under a Business Associate Agreement, careful forms, and clear limits on what ordinary web tools can carry.
Secure chat
Secure chat and calendar live inside the signed-in client portal — not on the public website. After login, the chat launcher opens an encrypted vendor channel when a BAA-backed messaging vendor is connected (TLS in transit; vendor encryption at rest, access controls, and audit logs).
Until the vendor is live, the portal chat panel explains the gate. That is intentional — it prevents PHI from landing in a non-compliant public widget.
What is not a secure clinical channel
- Ordinary consumer email or mailto forms
- SMS, iMessage, WhatsApp, Facebook, or Instagram
- Generic website chat tools without a signed BAA
- Calendar invites that include diagnoses or clinical narrative
Website safeguards
- HTTPS and security headers on the static site
- Chat vendor blocked until baaSigned is configured in the site build
- Inquiry forms require a non-PHI acknowledgment
- Crisis pathways point to 911 / 988 (this site is not emergency care)
Honest limit
HIPAA compliance is an organizational program — policies, training, vendor BAAs, and technical controls — not a badge a webpage can award itself. StoneCurrent’s site is engineered so PHI can stay on protected systems; the practice must finish BAAs, publish the Notice of Privacy Practices, and enable the secure vendor before clinical messaging goes live.