The security and privacy safeguards Liminal Desk uses to protect your practice data and your clients' health and personal information
HIPAA-Grade Design
Liminal Desk is built with HIPAA-grade security principles throughout. While no software alone constitutes full HIPAA compliance (which also requires organizational policies, training, and BAAs), the technical safeguards below meet or exceed the Security Rule's requirements for access controls, audit controls, integrity controls, and transmission security.
All data is encrypted using TLS 1.2+ during transmission and AES-256 at rest. Your client information is never exposed in plaintext outside the application.
Every database query is filtered by your authenticated identity. Your data is completely invisible to other practitioners — even at the database level, not just the application level.
Sessions auto-lock after 15 minutes of inactivity, following HIPAA best practices. This prevents unauthorized access if you step away from your device.
All accounts require email verification before access. Anonymous sign-ups are disabled. Only authenticated, verified users can access practice data.
Sensitive actions like digital agreement signatures are logged with forensic detail — including IP address, user agent, timestamp, and signer identity — for legal compliance and accountability.
Client portal links use unique, cryptographically random tokens with automatic expiration. Clients access only their own data through time-limited, non-guessable URLs — no account required.
Data is hosted on SOC 2 Type II compliant infrastructure with automated backups, redundant storage, and geographic distribution. Uploaded documents are stored in encrypted cloud storage buckets.
Electronic signatures are ESIGN Act and UETA compliant. Each signature captures the signer's full name, timestamp, IP address, and browser fingerprint. Audit logs are retained for 7 years.
Most independent, private-pay end-of-life doulas are not HIPAA covered entities. You typically become subject to HIPAA as a business associate only when a hospice, hospital, or other covered entity engages you and discloses protected health information so you can perform a function on its behalf. Either way, the information a doula holds — diagnosis, prognosis, advance directives, family dynamics — deserves the same technical safeguards.
Your responsibilities as a practitioner: