EN / ES
Sign In Start Free Trial

Trust & Security

How Sefton protects your data. Operated by Sefton Health, Inc.

Our role under HIPAA

Sefton is built to support HIPAA compliance. For Protected Health Information (PHI), Sefton Health, Inc. acts as a Business Associate of your practice (the covered entity), under a signed Business Associate Agreement. Your practice controls patient PHI; we process it only to provide the service.

Safeguards

  • Encryption in transit and at rest
  • Access controls and least-privilege; tenant isolation
  • Multi-factor and passkey (WebAuthn) authentication options
  • PHI-aware audit logging and incident response
  • Secrets management and security headers / origin controls

Our commitment on AI and your data

We do not sell your information, and we do not use PHI to train, fine-tune, or improve any AI or machine-learning model — first-party or third-party, general-purpose or special-purpose — except solely to deliver the feature you asked for to your own practice. This is a contractual, non-waivable commitment in our Business Associate Agreement, not just a policy statement. AI features provide administrative support only; your clinician reviews and is responsible for every note and code.

Sub-processors (PHI-bearing)

These vendors process PHI to provide the service and operate under signed Business Associate Agreements:

Sub-processorScopeBAA
Cloud infrastructure providerHIPAA-eligible hosting, PHI runtime, and AI/media processing when enabledSigned
OptumClearinghouse + ERA / remittanceSigned

Vendors kept out of PHI scope

VendorWhy no PHI
StripePayments only — subscription/payment payloads kept PHI-free
Apple APNsPush delivery — push payloads kept PHI-free
Google OAuthSign-in identity metadata only
GitHubSource control — PHI never committed

Change notice

We will update this page and provide notice by reasonable means before adding a new PHI-bearing sub-processor.

Certifications

SOC 2 Type I is in progress. We can provide available security attestations under NDA to customers on request. We do not overstate our certification status.

Reporting a concern

Security questions or reports: privacy@sefton.health. If you believe your privacy rights have been violated, you may also contact your provider (the covered entity) or the U.S. Department of Health and Human Services, Office for Civil Rights.

← Back to Legal Center · AI features: patient FAQ

sefton

Bilingual to the core — care, documentation, and billing in one platform.

Product

  • Features
  • Pricing
  • FAQ
  • Sign in
  • Start free trial

Legal

  • Privacy policy
  • Terms of service
  • Cookie policy
  • Accessibility

Compliance

  • Security
  • Business Associate Agreement
  • Legal center

Company

  • Contact
© Sefton — bilingual, billing-first practice management for allied health.