Your patients trust you.
You can trust us with their records.
Reviva is HIPAA compliant, and a Business Associate Agreement comes with every agreement — not as an upgrade. Here’s what that protects, in plain language, and what you control yourself.
What's protecting your patient records.
Not a list of acronyms. These are the controls doing the actual work, and every one of them is on for every account.
HIPAA compliant
Reviva is built to handle protected health information, and every account is covered.
BAA on every agreement
No upgrade, no add-on, no asking. Your Business Associate Agreement is included by default.
Encrypted in transit and at rest
Patient data is encrypted on the way to us and while it sits in our database.
Role-based access
Staff see what their role needs and nothing else. You configure it per role.
Audit logging
Record access and changes are logged, so you can answer "who saw this chart?"
Backed up continuously
Your records are backed up so a lost laptop or a bad day never loses a chart.
You didn’t go to school for compliance.
So here is the short version of what HIPAA asks of a practice like yours, what Reviva handles, and where the line sits between us.
What a BAA actually is
A Business Associate Agreement is the contract HIPAA requires between your practice and any vendor that touches patient information. Without one, using that vendor is itself a violation — no matter how secure the software is. Reviva includes a BAA with every agreement, so you are covered from day one.
What counts as PHI
Protected Health Information is anything that ties a health detail to a specific person: names alongside treatments, photos, appointment history, chart notes, even a phone number in a message thread. In practice, assume anything in your client record is PHI and treat it that way.
Why “HIPAA compliant software” is only half of it
HIPAA holds your practice responsible too. Compliant software gives you the controls — unique logins, role permissions, audit logs, secure messaging. Compliance happens when your team actually uses them. That is why we ship the controls on by default rather than leaving them for you to discover.
Texting and email, specifically
Ordinary SMS and personal email are not built for PHI. Reviva keeps client messaging inside the platform, where it is encrypted and logged against the client record, so your team can text a client about their appointment without moving PHI somewhere it should not go.
Your front desk doesn’t need to read chart notes.
Reviva ships with sensible defaults for each role, and every one of them is yours to change. Here’s where the lines sit out of the box.
| Permission | OwnerFull access, including billing, permissions, and integrations. | ManagerRuns the day-to-day. Everything except owner-level billing. | ProviderClinical work — charts, notes, and treatment plans. | Front deskBooking, check-in, and checkout. No clinical charting. |
|---|---|---|---|---|
| Client records | ||||
| View client list and contact details | Allowed for Owner: View client list and contact details | Allowed for Manager: View client list and contact details | Allowed for Provider: View client list and contact details | Allowed for Front desk: View client list and contact details |
| View full clinical chartFront desk sees booking and billing fields without the clinical note. | Allowed for Owner: View full clinical chart | Configurable for Manager: View full clinical chart | Allowed for Provider: View full clinical chart | Blocked for Front desk: View full clinical chart |
| View before & after photos | Allowed for Owner: View before & after photos | Configurable for Manager: View before & after photos | Allowed for Provider: View before & after photos | Blocked for Front desk: View before & after photos |
| Export client data | Allowed for Owner: Export client data | Configurable for Manager: Export client data | Blocked for Provider: Export client data | Blocked for Front desk: Export client data |
| Charting | ||||
| Create and sign own notes | Allowed for Owner: Create and sign own notes | Blocked for Manager: Create and sign own notes | Allowed for Provider: Create and sign own notes | Blocked for Front desk: Create and sign own notes |
| View another provider's notesUseful for group practices; off by default so providers only see their own panel. | Allowed for Owner: View another provider's notes | Configurable for Manager: View another provider's notes | Configurable for Provider: View another provider's notes | Blocked for Front desk: View another provider's notes |
| Amend a signed noteAmendments are always additive — the original stays in the audit trail. | Allowed for Owner: Amend a signed note | Blocked for Manager: Amend a signed note | Configurable for Provider: Amend a signed note | Blocked for Front desk: Amend a signed note |
| Payments | ||||
| Take a payment at checkout | Allowed for Owner: Take a payment at checkout | Allowed for Manager: Take a payment at checkout | Configurable for Provider: Take a payment at checkout | Allowed for Front desk: Take a payment at checkout |
| Issue a refund | Allowed for Owner: Issue a refund | Allowed for Manager: Issue a refund | Blocked for Provider: Issue a refund | Configurable for Front desk: Issue a refund |
| Edit service pricing | Allowed for Owner: Edit service pricing | Configurable for Manager: Edit service pricing | Blocked for Provider: Edit service pricing | Blocked for Front desk: Edit service pricing |
| View payouts and bank details | Allowed for Owner: View payouts and bank details | Blocked for Manager: View payouts and bank details | Blocked for Provider: View payouts and bank details | Blocked for Front desk: View payouts and bank details |
| Reporting | ||||
| View own performance | Allowed for Owner: View own performance | Allowed for Manager: View own performance | Allowed for Provider: View own performance | Configurable for Front desk: View own performance |
| View practice-wide reports | Allowed for Owner: View practice-wide reports | Allowed for Manager: View practice-wide reports | Configurable for Provider: View practice-wide reports | Blocked for Front desk: View practice-wide reports |
| View revenue and financials | Allowed for Owner: View revenue and financials | Configurable for Manager: View revenue and financials | Blocked for Provider: View revenue and financials | Blocked for Front desk: View revenue and financials |
| Staff & settings | ||||
| Invite or deactivate staff | Allowed for Owner: Invite or deactivate staff | Configurable for Manager: Invite or deactivate staff | Blocked for Provider: Invite or deactivate staff | Blocked for Front desk: Invite or deactivate staff |
| Edit roles and permissions | Allowed for Owner: Edit roles and permissions | Blocked for Manager: Edit roles and permissions | Blocked for Provider: Edit roles and permissions | Blocked for Front desk: Edit roles and permissions |
| Manage integrations | Allowed for Owner: Manage integrations | Blocked for Manager: Manage integrations | Blocked for Provider: Manage integrations | Blocked for Front desk: Manage integrations |
| View the audit log | Allowed for Owner: View the audit log | Configurable for Manager: View the audit log | Blocked for Provider: View the audit log | Blocked for Front desk: View the audit log |
Full access, including billing, permissions, and integrations.
Client records
- Allowed for Owner: View client list and contact detailsView client list and contact details
- Allowed for Owner: View full clinical chartView full clinical chartFront desk sees booking and billing fields without the clinical note.
- Allowed for Owner: View before & after photosView before & after photos
- Allowed for Owner: Export client dataExport client data
Charting
- Allowed for Owner: Create and sign own notesCreate and sign own notes
- Allowed for Owner: View another provider's notesView another provider's notesUseful for group practices; off by default so providers only see their own panel.
- Allowed for Owner: Amend a signed noteAmend a signed noteAmendments are always additive — the original stays in the audit trail.
Payments
- Allowed for Owner: Take a payment at checkoutTake a payment at checkout
- Allowed for Owner: Issue a refundIssue a refund
- Allowed for Owner: Edit service pricingEdit service pricing
- Allowed for Owner: View payouts and bank detailsView payouts and bank details
Reporting
- Allowed for Owner: View own performanceView own performance
- Allowed for Owner: View practice-wide reportsView practice-wide reports
- Allowed for Owner: View revenue and financialsView revenue and financials
Staff & settings
- Allowed for Owner: Invite or deactivate staffInvite or deactivate staff
- Allowed for Owner: Edit roles and permissionsEdit roles and permissions
- Allowed for Owner: Manage integrationsManage integrations
- Allowed for Owner: View the audit logView the audit log
Defaults shown. Permissions are set per role in Settings, and changes apply to everyone in that role immediately.
Five habits that keep a small practice compliant.
Compliant software gives you the controls. These are the five things worth doing with them — none of them takes more than a minute.
Give every person their own login
Shared accounts break your audit trail — you can no longer tell who opened a chart. One login per person, always.
Match the role to the job
Your front desk does not need clinical notes to book an appointment. Start people at the narrowest role that lets them work.
Deactivate staff the day they leave
Offboarding is the most commonly missed control in small practices. Deactivating takes seconds and closes the biggest hole.
Keep client conversations in the platform
Personal phones and inboxes are outside your compliance boundary. In-platform messaging keeps the record — and the protection — together.
Check the audit log after anything unusual
A departing employee, a disputed chart, a complaint. The log is there precisely so you can answer with facts instead of guesses.
Technical evaluator? Skip the marketing.
If you’re the person doing the security review — IT, a consultant, or a compliance officer — our Trust Center has the full control list and live monitoring status, continuously verified rather than screenshotted once a year.
- Control-by-control detail
- Subprocessors
- Monitoring status
- Document requests
trust.joinreviva.com
Bring your compliance questions to the demo.
We’ll walk through the BAA, show you the permissions screen with your own roles in it, and answer the awkward questions directly.