Two months free. Download LogBlues and let us prove it — no card, no contract. Start free →
LogBlues

HIPAA

Is LogBlues HIPAA compliant?

Yes. LogBlues is built to HIPAA’s Privacy, Security and Breach Notification rules from day one, and this page explains how. Patient records stay on the computers in your practice, encrypted. Each person signs in as themselves and sees only what their job needs. A security log records the sensitive actions. We sign a Business Associate Agreement with any clinic that asks, free. Send this page to whoever is asking you the question.

One thing first

Compliance is something a practice does. Software helps or gets in the way.

There is no government stamp that makes a piece of software “HIPAA compliant.” HIPAA puts its duties on the practice: its policies, its training, its agreements and how its staff work on a busy Thursday. What software can do is make the right thing the default and the wrong thing hard, and keep the record that proves it.

So this page is in two halves. The first says what LogBlues does for you. The second says what stays yours to do, and where LogBlues helps with that.

The rules

What HIPAA asks of software like LogBlues.

HIPAA is the United States law that protects protected health information, or PHI: anything in a chart that says who the patient is. Three of its rules matter for practice software.

  • The Privacy Rule says who may see or share PHI, and gives every patient the right to a copy of their own record.
  • The Security Rule says how electronic PHI must be protected: each user identified, access limited to the job, encryption, automatic sign-out, an audit trail, backups that can be restored, and a written risk analysis.
  • The Breach Notification Rule says what happens if unsecured PHI gets out: the practice tells the affected patients and the Department of Health and Human Services.

The practice is the “covered entity.” A vendor that handles PHI for the practice is a “business associate,” and the two sign a Business Associate Agreement, or BAA. LogBlues is built so that in normal use we never hold a readable record at all. That one decision makes everything below simpler.

Where the records live

On your machines. Not in our cloud.

Patients, notes, documents, images, schedules and billing are created and stored on the computers in your practice. Nothing in normal use sends them to LogBlues. We cannot produce a readable patient record on request, because we do not hold one. The app keeps working with no internet, because there is nothing it needs to fetch.

Blues, the assistant inside LogBlues, runs on a model on the clinic’s own computer. What a provider types to it stays on that computer.

Three things do touch our servers, and none of them is a chart:

  • Your account. The clinic’s name, staff email addresses and roles. No patient information.
  • Online patient forms, if you switch them on. A patient’s answers travel to your practice through our servers. They are erased once your practice has them, and within 30 days regardless.
  • Cloud backup, if you switch it on. An encrypted copy that we cannot open. The backup section below explains it.

Our servers are in the United States. Nothing crosses a border.

Encryption

Encrypted at rest and in transit.

At rest. The workspace database is encrypted with AES-256-GCM. The key is held in Windows’ own protected store, called DPAPI, never in a file we invented. Before the app trusts the machine it runs on, it checks that disk encryption is enabled and a screen lock is set. Turn on Windows device encryption or BitLocker on every workstation that holds clinical attachments; that covers the attached files and everything else on the disk. Portable exports are encrypted separately with a passphrase you choose.

In transit. Everything that travels, whether a sign-in, a cloud backup upload or an online form, goes over TLS, the same encryption your bank’s website uses.

Tamper-proof, not just secret. The encryption LogBlues uses is authenticated. A backup that has been altered refuses to open, rather than opening with changed data inside.

Who can see what

Each person signs in as themselves and sees only their job.

  • One login per person. There are no shared logins in LogBlues. Every action belongs to a named person.
  • Roles. Ten roles across twenty-six permissions decide which screens, dashboard cards and actions a person reaches. The front desk can book appointments without reading a clinical note. An administrator can take away more for one individual.
  • Blues obeys the same roles. The assistant is handed the permissions of the person using it, cannot read or write past them, and asks before every write.
  • Automatic lock. The workspace locks after an idle period the clinic sets: 15 or 30 minutes, or 1, 3, 6 or 8 hours. Choosing “never” is written to the security log.
  • A second door on sensitive results. Results marked sensitive ask again before they open. The provider gets a one-time code by email that expires in ten minutes, or verifies with Windows Hello or a device PIN. Every unlock is logged.
  • The security log. Exports, backups, protected-result verifications and security-policy changes are written down with what happened and when. Authorized staff read it on the Security screen.

The Security page goes through it layer by layer →

Backups

Backups you control, and a cloud copy we cannot read.

The Security Rule asks for a retrievable exact copy of electronic PHI and a plan for restoring it. LogBlues gives you two ways.

Encrypted local export. Built in and free. Complete, encrypted with a passphrase you choose, and runnable by you without asking us. A restore preview shows what is in a file before you restore it.

Cloud backup. Optional, and off until you switch it on. Each copy is encrypted on your own computer before it leaves, under a key that is generated on your computer and kept in Windows’ protected store. We never receive that key. What sits on our servers is scrambled text we cannot open, and neither can anyone who took it. Once a day a fresh copy goes up. A broken computer means an afternoon of setup on a new one, restored with one button and your recovery key, not a lost practice. Storage is 50 GB on Standard, 500 GB on Premium and 2 TB on Enterprise.

The recovery key is yours alone. It is shown once, and it can be saved to a file. Keep it somewhere safe that is not the same computer. We cannot recover it for you. That is the price of a backup nobody but you can read.

The agreement

A Business Associate Agreement, free, on request.

A BAA is the contract HIPAA requires between a practice and any vendor that creates, receives, keeps or transmits PHI on its behalf. We sign one with any clinic that asks, at no charge, on any plan. Write to us and we will send it and talk it through.

In plain words, ours commits us to use PHI only to provide the service to you; never to sell it, use it for marketing, or use it to train an AI model; to keep the safeguards described on this page; to report security incidents and breaches to you; and to return or destroy anything we hold when you leave.

Ask us for our Business Associate Agreement →

If something goes wrong

Breach notification, and what we would do.

The Breach Notification Rule is about unsecured PHI: records that whoever got them could read. PHI that is encrypted the way the Department of Health and Human Services describes is not unsecured. That is one reason LogBlues encrypts everywhere.

What that means in practice: a stolen laptop holds a database that is unreadable without the key in Windows’ protected store, and BitLocker covers the rest of the disk. The cloud copy is scrambled text to us and to anyone else. On our side there is no readable chart to expose.

What we would do. Under the Business Associate Agreement we report to you any security incident and any breach of unsecured PHI we become aware of, without unreasonable delay, with the information you need to meet your own deadlines. We would not sit on it.

What the practice does. Tells the affected patients and the Department of Health and Human Services within the deadlines the rule sets, at most sixty days after discovery. The security log gives you the what and when to start from.

What we do not do

No ads, no selling, no reading your charts.

  • We cannot read your charts. They are on your machines, and the cloud backup is encrypted with a key we never receive.
  • We do not sell patient data, or any other data, at any price.
  • No advertising, no trackers. The app has no third-party trackers, advertising kits or behavioural telemetry. The website has no analytics script and no cookie banner, because there are no cookies to consent to.
  • Your patient data never trains an AI model. Not ours, not anyone’s. Blues runs on your machine, and no prompt or answer is sent to a model vendor.
  • No biometrics reach us. If a provider verifies with Windows Hello, the match happens inside Windows. The app receives a yes or a no, never a fingerprint or a face.
  • Nothing kept after you leave. We do not claim a licence over your records and we do not keep a de-identified copy.

Your half

What stays the practice’s own responsibility.

HIPAA puts these on the practice, not on its software. LogBlues helps with each one, but cannot do them for you.

  • A written security risk analysis, reviewed at least once a year. It is the first thing an investigator asks for.
  • Policies and procedures, and staff trained on them, with the training recorded. The Compliance area in LogBlues keeps policies, procedures and safety checks in one place, each a dated record, and the written security policy exports as a document you can hand to an auditor or an insurer.
  • Someone named as the practice’s privacy and security officer.
  • Physical safeguards for the computers that hold LogBlues: disk encryption on, screens locked when walking away, machines that do not leave the building without a reason.
  • A backup routine and a restore drill. A backup that has never been restored is not a backup. Restore one onto a clean machine and write down the date.
  • Agreements with every vendor that touches PHI, not only us: a billing service, a clearinghouse, an email provider.
  • Patients’ access to their own records. LogBlues can answer a patient the same day, from the chart itself.

Checklist

A checklist you can copy.

  1. Every staff member has their own LogBlues login and their own role. No shared passwords.
  2. Windows device encryption or BitLocker is on for every computer that holds LogBlues.
  3. Automatic lock is set to an idle time that fits your front desk, and nobody walks away from an open screen.
  4. The second check on sensitive results is left on.
  5. Cloud backup is on, or a local export runs on a schedule. The recovery key is saved somewhere safe, away from that computer.
  6. One restore drill has been done, and the date is written down.
  7. A signed Business Associate Agreement with LogBlues, and with every other vendor that handles PHI.
  8. A written security risk analysis, dated within the last year.
  9. Policies and procedures live in the Compliance area.
  10. Someone is named as privacy and security officer, and someone reads the security log on a schedule.

The full checklist, with a calendar for staying compliant →

Passing it on

Send this page to whoever is asking.

The address is logblues.com/hipaa-compliance.html. If they want it in writing, or want the Business Associate Agreement itself, use the contact form and a person who works on the software will answer.

Contact form (general) — agreements and BAA requests
Contact form (security) — security questions and disclosure