HIPAA Policy

HIPAA Compliance
at Rewire.

Last updated: August 6, 2026  ·  Version 1.0  ·  Rewire App LLC

01 — Our Role

How Rewire fits within HIPAA

Rewire App LLC is not a healthcare provider, health plan, or healthcare clearinghouse and does not represent itself as a HIPAA Covered Entity. When a therapist, group practice, treatment facility, or other Covered Entity uses Rewire to create, receive, maintain, or transmit protected health information on its behalf, Rewire acts as that organization's Business Associate.

In that role, Rewire applies the safeguards and contractual commitments described here and in its Business Associate Agreement. Covered Entities remain responsible for their own HIPAA obligations, clinical decisions, workforce practices, and appropriate use of the platform.

02 — Administrative Safeguards

Governance, risk management, and workforce practices

Rewire maintains a written Security Risk Assessment and Security Policy addressing risks to the confidentiality, integrity, and availability of electronic protected health information. Rewire also maintains a workforce sanction policy and workforce security and privacy training requirements appropriate to each person's responsibilities.

These internal policy documents are maintained within Rewire's legal and compliance program and are available to covered-entity partners on request, subject to reasonable confidentiality and security controls.

03 — Technical Safeguards

Controls protecting electronic PHI

Rewire uses layered technical controls designed to limit access and protect information throughout its lifecycle:

04 — Business Associate Agreements

Contractual protection across the service chain

Rewire signs a Business Associate Agreement with covered-entity therapists and facilities when Rewire will handle PHI on their behalf. The current form and request process are available on our Business Associate Agreement page.

Rewire's upstream subprocessors that may participate in handling PHI are also covered by BAAs: Anthropic for AI processing, Supabase for database and authentication infrastructure, and Cloudflare for application hosting and edge services. Rewire limits disclosures to what is reasonably necessary to provide and secure the service.

05 — Breach Notification

Notice to covered-entity partners

If Rewire discovers a breach of unsecured PHI, Rewire will notify affected Covered Entities without unreasonable delay and no later than 10 business days after discovery. Rewire will provide the information required for the Covered Entity's assessment and notifications to the extent that information is known and will supplement the notice as additional material facts become available.

06 — Incident Response

Prepared response and recovery

Rewire maintains a written incident-response plan for identifying, containing, investigating, documenting, and recovering from security incidents. The plan establishes responsibilities, escalation paths, evidence-preservation expectations, and post-incident review procedures, including coordination with affected covered-entity partners where PHI may be involved.

07 — Contact

BAA requests and compliance questions

Covered entities may request a BAA, supporting compliance materials, or answers to HIPAA-related questions by emailing privacy@rewire-emdr.com.