1 · Data purpose
Collect only what the workflow needs
Map every patient field, message, assessment, attachment, log, export, and integration to a defined purpose, owner, retention rule, and deletion process.
A mental health platform has to fit the real work: who can see patient information, how consent is handled, what happens when risk language appears, which events are auditable, where AI enters the data path, and how staff carry the result into care.
Updated July 28, 2026 · Educational information, not legal advice
The direct answer
HIPAA compliance is not a product badge or federal software certification. A practice must evaluate the platform in its intended use: execute required Business Associate Agreements, complete a risk analysis, restrict access, protect and review activity, train the workforce, maintain contingency and incident procedures, and verify that every vendor receiving electronic protected health information is inside the approved data path.
Ask the vendor to demonstrate each control in the workflow your practice plans to use. A security page or signed contract alone cannot answer these questions.
1 · Data purpose
Map every patient field, message, assessment, attachment, log, export, and integration to a defined purpose, owner, retention rule, and deletion process.
2 · Contract chain
Confirm which organization is the covered entity or business associate, who receives ePHI, what each agreement covers, and how subprocessor changes are disclosed.
3 · Access
Use test accounts to prove that learners, assigned clinicians, organization administrators, support personnel, and unaffiliated users see only what their work requires.
4 · Auditability
Identify which access, assignment, alert, consent, export, documentation, and administrative events are recorded, who reviews them, and how anomalies are handled.
5 · Clinical boundary
Document what the software detects, what it shows the user, when it alerts staff, who owns follow-up, and how the platform avoids implying diagnosis, treatment, or emergency response.
6 · Operations
Review onboarding, termination, access recertification, incident response, recovery, vendor changes, risk re-analysis, staff training, and the handoff into the EHR or practice process.
Evaluate the product, not the category label
Digital Wellness Academy is built for structured education and engagement between visits. Its evaluation should connect each technical control to a visible provider or learner workflow.
Learner, provider, and organization functions are separated. Provider visibility is tied to the assigned relationship rather than a global patient directory.
Courses, assessments, guided practice, check-ins, and journals create reviewable signals without presenting education as diagnosis or a replacement for care.
The MAIA distress classifier evaluates text before an AI response. The workflow fails closed when classification is unavailable and can surface crisis resources and provider alert episodes when the configured threshold is met.
Alerts, patient context, documentation support, and review states give the practice a visible work queue rather than leaving safety signals buried inside chat transcripts.
Security-relevant application activity and alert-state changes can be retained for review. The practice still defines review cadence, retention, and escalation policy.
Practice-branded instances separate organizational configuration and workflow. A BAA and documented production data map are required before ePHI is introduced.
“Mental health platform” can mean several different products. A practice should not buy a familiar category and assume it covers every workflow.
| Platform category | Primary job | Evidence to request | Boundary |
|---|---|---|---|
| Telehealth | Secure video or messaging visits | Session access, participant controls, recording rules, consent, and BAA scope | Does not automatically provide an EHR or structured between-visit program |
| EHR / practice management | Clinical record, scheduling, billing, and core operations | Permissions, chart access, amendments, exports, billing access, audit, and integrations | Education and longitudinal skill practice may be limited |
| Digital Wellness Academy | Structured education, guided skill practice, assessments, and provider context between visits | Role scoping, assignment, consent, alerts, provider review, AI data path, and audit events | Not video telehealth, an EHR, scheduling, billing, or emergency response |
The answers depend on the job the software will perform. Telehealth, an EHR, practice management, and between-visit education are related categories, not interchangeable products.
There is no permanent federal list or software certification that makes a platform compliant in every use. Therapists should shortlist products by workflow, then verify the BAA, access controls, audit records, current subprocessor scope, configuration, and their own practice procedures.
For secure video or messaging, evaluate participant access, waiting rooms, recording and transcript rules, encryption, session links, support access, auditability, the BAA, and how the telehealth vendor protects health information. The practice must also configure and operate the service appropriately.
Price does not establish privacy or security. A free tier may exclude a BAA, specific controls, or the service scope a therapy practice needs. Verify the exact plan and terms before conducting telehealth sessions or entering patient data.
Start with unique accounts, role-based access, a secure client portal when needed, consent, audit records, retention controls, data export, incident procedures, and an understandable patient experience. Then evaluate scheduling, billing, intake forms, treatment-plan, EHR, or education features only if they match the intended workflow.
Yes, as a complementary workflow. DWA handles structured education and between-visit engagement; the practice decides how assignments, alerts, summaries, and documentation enter its electronic health record. Any automated integration is scoped and reviewed for the specific deployment.
A well-governed platform can simplify assignment, improve continuity, and make patient questions or risk signals visible. Poor scoping can expose confidential information, create alert fatigue, fragment the record, or imply that software replaces a mental health professional. Governance determines which outcome the practice gets.
An enterprise plan, privacy toggle, or promise not to train on customer data does not answer whether a model vendor can receive ePHI. Document the exact prompt content, preprocessing, model route, logging, retention, support access, contractual status, and fallback behavior.
DWA’s current coaching path uses OpenRouter-configured models and a separately hosted MAIA distress classifier. A practice considering PHI-bearing coaching must approve that actual production path and current vendor terms. DWA does not claim that clinical prompts are silently rerouted to a different vendor.
Example: OpenAI’s BAA eligibility and processThe completed evaluation should leave the practice with evidence, named owners, and an explicit go/no-go decision.
Bring your roles, patient journey, current EHR handoff, safety policy, consent model, and AI boundary. The review maps each requirement to a visible platform control or names the gap before go-live.