HIPAA Compliance
Last updated: September 15, 2026
Neurotive works with healthcare and wellness practices, and we take the Health Insurance Portability and Accountability Act (HIPAA) seriously in how we build and operate systems on our clients' behalf. This page explains our approach and, separately, how this website itself (neurotive.io) handles data.
This Website Does Not Collect Protected Health Information
The forms on neurotive.io (contact form, service inquiry forms, newsletter signup) are for business inquiries only — name, email, phone, company, and your message. Please do not submit Social Security numbers, insurance details, diagnoses, treatment history, or any other protected health information (PHI) through this website. If you are a patient looking to reach one of our clients' practices, please contact that practice directly rather than through this site.
Our Role for Client Projects
When our engagement with a client involves building or managing a system that does handle PHI — a patient portal, an online booking system tied to medical history, or a CRM workflow integrated with a practice management/EHR system — we act as, or work alongside, a Business Associate under HIPAA. That work is governed by the terms of that specific client engagement, not by this website's Terms of Service.
Business Associate Agreements (BAAs)
Before any project involves creating, receiving, maintaining, or transmitting PHI on a client's behalf, we execute a Business Associate Agreement (BAA) with that client, and require BAAs from any sub-processor or vendor (hosting, forms, analytics) that will touch that data. No PHI is handled on a client project until the relevant BAAs are in place.
Technical and Administrative Safeguards
For projects that involve PHI, we apply safeguards consistent with the HIPAA Security Rule, including:
- Encryption of data in transit and at rest
- Role-based access controls, limiting PHI access to team members who need it for the project
- Audit logging for systems that store or transmit PHI
- Secure, HIPAA-eligible hosting infrastructure
Compliant Marketing Practices
We also help clients avoid common HIPAA pitfalls in marketing itself — for example, ad platforms' restrictions on using PHI for ad targeting or retargeting, patient testimonial and review-request practices that respect patient privacy, and secure handling of any patient-facing forms we build.
Questions or Concerns
If you have a question about how a specific client project handles PHI, or a concern about our HIPAA practices, email ask@neurotive.io or call +1 (409) 302 2805 and we will respond promptly.




