← abaiq.ai
ABAIQ™
HYBREU DIGITAL LLC · doing business as ABAIQ
9555 SW 175th Terrace #799, Palmetto Bay, Florida 33157
support@abaiq.ai · abaiq.ai

Security & Development Practices

Security & Development Practices

How ABAIQ protects clinical data: architecture, safeguards, vendors and compliance posture.

DocumentSecurity & Development Practices · ABAIQ-SEC
Version1.1 (reissued in the current format; content effective June 3, 2026)
Effective dateJune 3, 2026
Applies toThe ABAIQ extension, the web platform and the QA Suite
Related documentsPrivacy Policy · Terms of Service · Business Associate Agreement · QA Suite Terms of Use

1. Overview

ABAIQ is an AI-powered documentation assistant for Applied Behavior Analysis (ABA) professionals. It helps clinicians generate session note drafts faster by working alongside any web-based practice management system through a Chrome browser extension.

ABAIQ is not an electronic health record (EHR), a medical record system, or a clinical decision-making tool. It is a documentation productivity tool designed with healthcare data security as a foundational requirement, not an afterthought.

This document describes the security architecture, safeguards, and development practices that ABAIQ follows to protect your clinical data and maintain compliance with the HIPAA Security Rule.

2. Data Architecture & Flow

Understanding how your data moves through ABAIQ is critical to evaluating our security posture. Here is the complete data flow:

  1. The Chrome extension reads clinical session data that is already visible on your screen within your practice management system. It does not access any backend systems, APIs, or databases of the platform you are using.
  2. Your session inputs are sent over an encrypted (TLS 1.2+) connection to the ABAIQ backend API, which requires a valid authentication token for every request.
  3. The ABAIQ backend — hosted on Amazon Web Services (AWS) HIPAA-eligible infrastructure under a Business Associate Addendum — forwards the session data to our AI providers, with whom we maintain Business Associate Agreements (BAAs). The AI providers process the data in real-time via streaming.
  4. The generated clinical note draft is streamed back to your browser for review. You control whether to accept, edit, or discard the note.
  5. Once you close the extension sidebar or export your note, no copy of the generated note remains on ABAIQ servers. For the base note-writing feature, we do not store the content of clinical notes. The optional QA Suite is an exception: if you enable it and send a note for supervisory review, that note is transmitted and retained on BAA-covered AWS infrastructure, encrypted, as described in Section 6 and the QA Suite Terms of Use.

Key principle: for the base note-writing feature, clinical note content passes through ABAIQ but is not stored by ABAIQ. Our AI providers operate under BAAs with a Zero Data Retention policy, meaning session data is not retained or used for model training. The optional QA Suite, when enabled, does retain notes you send for supervisory review, on BAA-covered infrastructure, as described in Section 6.

3. Administrative Safeguards

Administrative safeguards establish the policies, procedures, and organizational measures to manage security:

4. Technical Safeguards

Technical safeguards are the technology-based controls that protect data and control access:

🔐 Encryption in transit: All data transmitted between the extension, our API, and our AI providers is encrypted using TLS 1.2 or higher.
🔒 Encryption at rest: Account metadata and user profile data stored in our database are encrypted at rest by our infrastructure provider.
🔑 Token-based authentication: Every API request to the ABAIQ backend requires a valid, time-limited authentication token verified against our auth system.
🚧 No PHI in URLs: Clinical data is transmitted exclusively via encrypted POST request bodies, never in URL parameters or query strings.
📝 Audit logging: Account, authentication, and credit operations are recorded in an append-only audit log with timestamps, user identifiers, and request metadata for accountability and incident investigation.
🛠 Secure development: Code changes undergo review before deployment. Dependencies are regularly audited for known vulnerabilities.

5. Physical Safeguards

ABAIQ does not operate its own data centers or physical servers. All infrastructure is hosted by third-party cloud providers that maintain robust physical security controls:

6. Data Minimization

We follow the principle of collecting and processing only the minimum amount of data necessary to deliver the service:

7. Business Associate Agreements

Business Associate Agreements are a cornerstone of HIPAA compliance when third parties handle protected health information:

8. Third-Party Vendors

ABAIQ uses a limited number of third-party services to operate. We evaluate each vendor for security practices and compliance posture:

Service Category Purpose Data Handled
Cloud Infrastructure (Amazon Web Services) Backend hosting on HIPAA-eligible infrastructure Base note-writing: session data in transit, not stored. QA Suite: note content stored encrypted. All under a BAA.
Authentication & Database User registration, login, account storage Account, usage, and billing data only (no patient PHI; BAA not required)
AI Providers Real-time clinical note generation Session inputs (processed under Zero Data Retention, not retained)
Payment Processor Subscription billing Billing details (we never see full card numbers; no PHI)
SMS Provider Multi-factor authentication delivery Phone number (for OTP codes only; no PHI)

Each provider maintains their own security certifications and compliance standards. Our AI providers and AWS operate under Business Associate Agreements with ABAIQ.

9. Extension Permissions & Behavior

Transparency about what the ABAIQ Chrome extension can and cannot do:

10. Compliance Posture

ABAIQ implements administrative, technical, and physical safeguards consistent with the HIPAA Security Rule (45 CFR Part 164, Subparts A and C). Key aspects of our compliance posture:

Important: ABAIQ is a documentation assistance tool. It does not replace or reduce the compliance obligations of covered entities or business associates under HIPAA. You are responsible for ensuring your overall use of ABAIQ complies with HIPAA and applicable state regulations. All generated notes must be reviewed, verified, and approved by a qualified professional before clinical use.

11. HIPAA Compliance — Frequently Asked Questions

Is ABAIQ HIPAA compliant? Yes. ABAIQ is operated by Hybreu Digital LLC as a HIPAA Business Associate and is engineered to comply with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. ABAIQ maintains signed Business Associate Agreements with every subprocessor that processes Protected Health Information (PHI), offers a BAA to its own customers at abaiq.ai/baa.html, runs all AI processing under Zero Data Retention, and encrypts data in transit and at rest. The base note-writing feature does not store the content of generated clinical notes; the optional QA Suite, when enabled, retains notes sent for supervisory review on BAA-covered AWS infrastructure, encrypted, with only client initials transmitted and a signed data-sharing consent required first, as described in the QA Suite Terms of Use.

What laws does ABAIQ operate under? ABAIQ complies with HIPAA and its implementing regulations, including:

Who are the parties under HIPAA? The clinician or ABA agency that uses ABAIQ is a Covered Entity (or a Business Associate of one). ABAIQ is a Business Associate of that clinician or agency, governed by the customer BAA at abaiq.ai/baa.html. ABAIQ's AI and cloud-infrastructure providers (Anthropic, OpenAI, AWS) are subcontractors of ABAIQ, each under its own signed BAA.

Does ABAIQ need a BAA with my EMR or practice-management platform (such as ABA Matrix, CentralReach, Rethink, Motivity, or Catalyst)? No — and HIPAA does not contemplate one.

In short: ABAIQ holds the BAAs HIPAA actually requires — with its customers and with the subprocessors that process PHI. A BAA between ABAIQ and a separate EMR vendor is not required by HIPAA, because the two are independent Business Associates of the same Covered Entity, not subcontractors of one another.

12. Related Policies

For additional information about how we handle your data and the terms governing the Service, please review:

13. Contact Us

For security questions, BAA requests, or to report a vulnerability, contact us:

Hybreu Digital LLC (DBA ABAIQ)
Email: support@abaiq.ai

ABAIQ Security & Development Practices · Effective June 3, 2026Hybreu Digital LLC · ABAIQ™