HIPAA compliant · BAA included on every account

Your patients trust you. You can trust us with their records.

Reviva is HIPAA compliant, and a Business Associate Agreement comes with every agreement — not as an upgrade. Here’s what that protects, in plain language, and what you control yourself.

BAA includedEncrypted in transit & at restPer-role access control
At a glance

What's protecting your patient records.

Not a list of acronyms. These are the controls doing the actual work, and every one of them is on for every account.

HIPAA compliant

Reviva is built to handle protected health information, and every account is covered.

BAA on every agreement

No upgrade, no add-on, no asking. Your Business Associate Agreement is included by default.

Encrypted in transit and at rest

Patient data is encrypted on the way to us and while it sits in our database.

Role-based access

Staff see what their role needs and nothing else. You configure it per role.

Audit logging

Record access and changes are logged, so you can answer "who saw this chart?"

Backed up continuously

Your records are backed up so a lost laptop or a bad day never loses a chart.

HIPAA, plainly

You didn’t go to school for compliance.

So here is the short version of what HIPAA asks of a practice like yours, what Reviva handles, and where the line sits between us.

What a BAA actually is

A Business Associate Agreement is the contract HIPAA requires between your practice and any vendor that touches patient information. Without one, using that vendor is itself a violation — no matter how secure the software is. Reviva includes a BAA with every agreement, so you are covered from day one.

What counts as PHI

Protected Health Information is anything that ties a health detail to a specific person: names alongside treatments, photos, appointment history, chart notes, even a phone number in a message thread. In practice, assume anything in your client record is PHI and treat it that way.

Why “HIPAA compliant software” is only half of it

HIPAA holds your practice responsible too. Compliant software gives you the controls — unique logins, role permissions, audit logs, secure messaging. Compliance happens when your team actually uses them. That is why we ship the controls on by default rather than leaving them for you to discover.

Texting and email, specifically

Ordinary SMS and personal email are not built for PHI. Reviva keeps client messaging inside the platform, where it is encrypted and logged against the client record, so your team can text a client about their appointment without moving PHI somewhere it should not go.

Access control

Your front desk doesn’t need to read chart notes.

Reviva ships with sensible defaults for each role, and every one of them is yours to change. Here’s where the lines sit out of the box.

Allowed by default Off by default, can be enabled Not available to this role

Full access, including billing, permissions, and integrations.

Client records

  • Allowed for Owner: View client list and contact detailsView client list and contact details
  • Allowed for Owner: View full clinical chartView full clinical chartFront desk sees booking and billing fields without the clinical note.
  • Allowed for Owner: View before & after photosView before & after photos
  • Allowed for Owner: Export client dataExport client data

Charting

  • Allowed for Owner: Create and sign own notesCreate and sign own notes
  • Allowed for Owner: View another provider's notesView another provider's notesUseful for group practices; off by default so providers only see their own panel.
  • Allowed for Owner: Amend a signed noteAmend a signed noteAmendments are always additive — the original stays in the audit trail.

Payments

  • Allowed for Owner: Take a payment at checkoutTake a payment at checkout
  • Allowed for Owner: Issue a refundIssue a refund
  • Allowed for Owner: Edit service pricingEdit service pricing
  • Allowed for Owner: View payouts and bank detailsView payouts and bank details

Reporting

  • Allowed for Owner: View own performanceView own performance
  • Allowed for Owner: View practice-wide reportsView practice-wide reports
  • Allowed for Owner: View revenue and financialsView revenue and financials

Staff & settings

  • Allowed for Owner: Invite or deactivate staffInvite or deactivate staff
  • Allowed for Owner: Edit roles and permissionsEdit roles and permissions
  • Allowed for Owner: Manage integrationsManage integrations
  • Allowed for Owner: View the audit logView the audit log

Defaults shown. Permissions are set per role in Settings, and changes apply to everyone in that role immediately.

Your half of the work

Five habits that keep a small practice compliant.

Compliant software gives you the controls. These are the five things worth doing with them — none of them takes more than a minute.

  1. Give every person their own login

    Shared accounts break your audit trail — you can no longer tell who opened a chart. One login per person, always.

  2. Match the role to the job

    Your front desk does not need clinical notes to book an appointment. Start people at the narrowest role that lets them work.

  3. Deactivate staff the day they leave

    Offboarding is the most commonly missed control in small practices. Deactivating takes seconds and closes the biggest hole.

  4. Keep client conversations in the platform

    Personal phones and inboxes are outside your compliance boundary. In-platform messaging keeps the record — and the protection — together.

  5. Check the audit log after anything unusual

    A departing employee, a disputed chart, a complaint. The log is there precisely so you can answer with facts instead of guesses.

Technical evaluator? Skip the marketing.

If you’re the person doing the security review — IT, a consultant, or a compliance officer — our Trust Center has the full control list and live monitoring status, continuously verified rather than screenshotted once a year.

  • Control-by-control detail
  • Subprocessors
  • Monitoring status
  • Document requests
Open the Trust Center

trust.joinreviva.com

Bring your compliance questions to the demo.

We’ll walk through the BAA, show you the permissions screen with your own roles in it, and answer the awkward questions directly.