HIPAA standards for end-of-life doulas

    The security and privacy safeguards Liminal Desk uses to protect your practice data and your clients' health and personal information

    HIPAA-Grade Design

    Liminal Desk is built with HIPAA-grade security principles throughout. While no software alone constitutes full HIPAA compliance (which also requires organizational policies, training, and BAAs), the technical safeguards below meet or exceed the Security Rule's requirements for access controls, audit controls, integrity controls, and transmission security.

    Encryption in Transit & at Rest

    All data is encrypted using TLS 1.2+ during transmission and AES-256 at rest. Your client information is never exposed in plaintext outside the application.

    Row-Level Security (Data Isolation)

    Every database query is filtered by your authenticated identity. Your data is completely invisible to other practitioners — even at the database level, not just the application level.

    Automatic Session Timeout

    Sessions auto-lock after 15 minutes of inactivity, following HIPAA best practices. This prevents unauthorized access if you step away from your device.

    Authentication & Access Control

    All accounts require email verification before access. Anonymous sign-ups are disabled. Only authenticated, verified users can access practice data.

    Audit Logging

    Sensitive actions like digital agreement signatures are logged with forensic detail — including IP address, user agent, timestamp, and signer identity — for legal compliance and accountability.

    Client Portal Security

    Client portal links use unique, cryptographically random tokens with automatic expiration. Clients access only their own data through time-limited, non-guessable URLs — no account required.

    Infrastructure & Storage

    Data is hosted on SOC 2 Type II compliant infrastructure with automated backups, redundant storage, and geographic distribution. Uploaded documents are stored in encrypted cloud storage buckets.

    Digital Signature Compliance

    Electronic signatures are ESIGN Act and UETA compliant. Each signature captures the signer's full name, timestamp, IP address, and browser fingerprint. Audit logs are retained for 7 years.

    Does HIPAA apply to your doula practice?

    Most independent, private-pay end-of-life doulas are not HIPAA covered entities. You typically become subject to HIPAA as a business associate only when a hospice, hospital, or other covered entity engages you and discloses protected health information so you can perform a function on its behalf. Either way, the information a doula holds — diagnosis, prognosis, advance directives, family dynamics — deserves the same technical safeguards.

    Read the full guide: HIPAA compliance for death doulas

    Your responsibilities as a practitioner:

    • Use a strong, unique password for your account.
    • Do not share your login credentials with anyone.
    • Lock your device when stepping away during sessions.
    • Ensure client portal links are shared over secure channels (encrypted email or messaging).
    • Review and update advance directive records regularly with clients.
    • If you operate under HIPAA, ensure your organization has a BAA in place with your hosting provider.