ABA clinics handle some of the most sensitive patient data in healthcare — diagnoses, behavioral assessments, session notes, caregiver information, and insurance details. Choosing software that treats HIPAA as an afterthought puts your practice, your clients, and your reputation at risk. BRDS was built from the ground up to align with HIPAA requirements and support your compliance responsibilities.
HIPAA-Aligned Architecture
Our platform supports secure handling of Protected Health Information (PHI) with role-based access controls, data minimization principles, and controlled data environments. We follow best practices under the Health Insurance Portability and Accountability Act and its associated security and privacy requirements.
Encryption Everywhere
Data encrypted in transit (HTTPS/TLS) and at rest using industry standards.
Role-Based Access
Principle of least privilege — BCBAs, RBTs, and admins see only what their role requires.
On-Staff HIPAA Officer
Dedicated HIPAA-Compliance Security Officer overseeing our security program 24/7.
Business Associate Agreements
BAAs available for all applicable vendor and client relationships as required.
No Unauthorized Data Sharing
We do not sell, rent, or share Protected Health Information. Any use or disclosure of PHI is strictly limited to authorized purposes and governed by applicable agreements. When PHI is processed within our hosted environment, we work with trusted infrastructure providers that support HIPAA compliance and execute BAAs with all applicable vendors.
Flexible, Client-Controlled Data Options
For organizations requiring additional control, BRDS supports configurations where sensitive data remains stored locally on client-managed devices, with no PHI transmitted to or stored on our servers. This gives you flexibility during pilot programs or in environments with strict data residency requirements.
Security Across the Full Platform
HIPAA compliance isn't limited to one module — it covers your entire workflow. Whether your team is using clinical data collection, practice management, or insurance billing, the same security standards apply. Session security, timeout controls, internal security reviews, and secure development practices are maintained continuously.
For full technical details, audit documentation, or BAA requests, visit our Security & HIPAA Compliance page or contact our security team at info@imisshtml.com.