HIPAA Compliance & Security Statement

Effective Date: August 12, 2026

At Varalume, we understand that protecting client trust and sensitive health data is fundamental to mental health practice. Varalume is engineered from the ground up to comply fully with the HIPAA Privacy, Security, and Breach Notification Rules, as well as the HITECH Act.

1. Business Associate Agreement (BAA)
Under HIPAA, any software handling Protected Health Information (PHI) for a covered entity must execute a Business Associate Agreement. Varalume, LLC automatically executes a binding, legally compliant BAA with every registered practitioner upon account creation and onboarding. We strictly mandate enterprise-level BAAs with all underlying sub-processors, including server hosting, database infrastructure, and telehealth video pipelines.

2. Technical Safeguards
Varalume enforces strict technical measures to safeguard electronic Protected Health Information. Encryption in Transit and at Rest: Data moving between clinicians, clients, and our servers is encrypted using TLS 1.3 protocols with 256-bit encryption; data at rest is encrypted using AES-256. Strict Tenant Isolation: Practice data is logically isolated. Role-Based Access Control: Access to PHI is restricted by permission levels set by the practice owner. Audit Controls: Immutable audit logs track access, modifications, and deletions of clinical notes and client charts.

3. Artificial Intelligence & PHI Protection
Our AI Clinical Insight Engine™ and administrative tools are engineered specifically for clinical environments with strict data boundaries. Zero Training Policy: Identifiable client data, session transcripts, and clinical notes are never used to train AI models. Data Ephemerality: Audio and raw session recordings used for administrative drafting are processed in memory and purged immediately after the structured note is generated. Clinician Autonomy: AI tools act strictly as drafting assistants, while clinicians retain full control over final records.

4. Physical & Infrastructure Security
Varalume utilizes top-tier, SOC 2 Type II and HITRUST-certified cloud data center infrastructure, including AWS and Supabase. Physical safeguards include 24/7/365 security monitoring and biometric access controls at data center facilities, along with geographically redundant backups and automatic failovers to prevent data loss.

5. Administrative Safeguards
Security Awareness: All Varalume employees undergo mandatory HIPAA security training and background checks. Principle of Least Privilege: Internal staff access is limited to what is necessary for technical maintenance and support, subject to strict audit trails. Incident Response: We maintain an active Incident Response Plan and enforce a strict 10-business-day internal reporting window to notify practices of security incidents, exceeding federal minimum standards.

Security Inquiries & Reporting
If you have questions about our security practices or need to report a potential vulnerability, please contact our Security & Compliance Officer at: security@varalume.ai
Varalume, LLC — Compliance Department