StillpointStillpoint
How It Works
Features
Pricing
Log InGet Started

Help Center

Guides, tutorials, and answers to help you get the most out of Stillpoint.

Topics

  • Getting Started
  • Dashboard & Analytics
  • Appointments & Availability
  • Clients & Notes
  • Services & Practitioners
  • Invoices & Claims
  • Booking Page & Website
  • Settings & Subscription
  • Scheduling
  • Clinical
  • Marketing
  • Integrations
Help/Settings & Subscription/HIPAA Compliance & Security
HIPAA Compliance & Security

HIPAA Compliance & Security

Stillpoint provides built-in tools to help your practice meet HIPAA requirements. The Compliance page centralizes your BAA status, audit logging, data retention settings, and encryption information.

Accessing Compliance Settings

Navigate to Settings > Compliance in the sidebar. The page is organized into four tabs: Status, Audit Log, Retention, and Encryption.

Business Associate Agreement (BAA)

The BAA is the legal agreement between your practice (the Covered Entity) and Stillpoint (the Business Associate) governing how Protected Health Information (PHI) is handled.

Accepting the BAA

  1. Open the Status tab on the Compliance page
  2. Click Review & Accept BAA
  3. Read the full agreement in the modal
  4. Enter your Covered Entity name if it differs from your practice name
  5. Click Accept to enable HIPAA mode

Once accepted, the page shows the BAA version, acceptance date, and who accepted it. HIPAA-compliant features (audit logging, data retention controls, encryption info) become available.

Viewing the BAA

After acceptance, click View Agreement to re-read the full BAA at any time.

Audit Log

The audit log records every access to Protected Health Information across your practice:

  • Who accessed the data (practitioner name and role)
  • What was accessed (client record, note, form submission)
  • When the access occurred
  • Action type (view, create, update, delete)

Access the audit log from the Audit Log tab. The log is searchable and filterable, and it is retained according to your data retention policy.

Data Retention

Configure how long PHI records are kept before becoming eligible for deletion:

  1. Open the Retention tab
  2. Select a retention period (5, 6, 7, or 10 years)
  3. Click Save Settings

HIPAA requires a minimum of 6 years. The default is 7 years. Some states may require longer periods -- consult your compliance officer for specific requirements.

Encryption

The Encryption tab provides information about how your data is protected:

  • At rest -- All data stored in the database is encrypted using AES-256
  • In transit -- All connections use TLS 1.2 or higher
  • Clinical notes -- Encrypted at the application layer with practice-specific keys
  • Backups -- Database backups are encrypted and stored in a separate region

Quick Stats

When HIPAA mode is active, the Status tab displays summary cards showing:

  • HIPAA Mode status (Active)
  • Total audit events recorded
  • Current BAA version

Tips

  • Accept the BAA before storing any PHI in Stillpoint
  • Review the audit log periodically to monitor access patterns
  • Set your retention period to match your state's requirements, not just the federal minimum
  • The BAA must be accepted by a practice owner or admin

Related Articles

Practice Settings

Update your practice name, timezone, and contact information.

Notification Settings

Configure email and SMS notification preferences.

Get Started

Ready when you are.

Join wellness practitioners who use Stillpoint to fill their schedule and focus on what matters most.

Start Your Free Practice
StillpointStillpoint

Scheduling software for wellness practitioners. Beautiful, simple, and built with care.

MADE IN CANADA

FEATURES

  • Booking & Intake
  • Team Scheduling
  • Group Classes
  • Payments
  • Reminders
  • Clinical Notes
  • Practice Website
  • AI Assistant
  • HIPAA Compliance
  • Integrations & Import
  • Multiple Locations
  • Waitlists
  • Analytics
  • Reviews
  • Email Templates
  • Appointment Management
  • Client Portal
  • Email Automations
  • Re-engagement
  • Recurring Appointments
  • Email Preferences

PRODUCT

  • Features
  • Pricing
  • How It Works
  • Compare
  • Make the Switch
  • Blog
  • FAQ
  • About

LEGAL

  • Privacy Policy
  • Terms of Service

SUPPORT

  • Help Center
  • help@withstillpoint.com

© 2026 Stillpoint Technologies Inc. All rights reserved.

Built for the people who help people.