Relvema가 보호 대상 건강 정보를 처리하는 방법과 이를 당사에 맡기는 공인 치료사 및 관련 기관에 어떤 의미가 있는지 설명합니다.
HIPAA 고지 읽기
Relvema was designed specifically for licensed therapists and the protected health information (PHI) they work with. HIPAA compliance is not an afterthought — it shapes every architectural decision we make.
As a Business Associate under HIPAA, Relvema is responsible for safeguarding any PHI that passes through or is stored in the platform on behalf of therapists who are covered entities.
Session audio recordings uploaded through the therapist portal or the patient app are stored encrypted in Google Cloud Storage and processed only to generate transcripts and AI summaries.
Transcripts, session summaries, mood scores, and homework assignments are stored in Firestore under strict per-user access rules. Patient names and email addresses are stored solely to maintain the therapist-patient connection record.
We do not sell, share, or use any PHI for advertising purposes. Data is never used to train external AI models.
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption managed by Google Cloud KMS.
Firestore security rules enforce row-level access: therapists can only read data for patients explicitly connected to their account. Server-side API routes use the Firebase Admin SDK with service account credentials stored in Google Secret Manager — never in source code or environment files.
Session audio files are accessed only through signed, time-limited URLs. Raw audio is never exposed directly to the browser.
Relvema has signed a Business Associate Agreement (BAA) with Google Cloud, covering all Firebase and Google Cloud services used to store and process PHI. This satisfies the HIPAA requirement for covered entities to have a BAA with every business associate that handles PHI on their behalf.
All Relvema therapists — on every plan — receive a BAA with Relvema directly, effective upon account creation. You can review the full BAA at relvema.com/legal/baa.
For compliance questions or to request a countersigned PDF copy of the BAA, contact compliance@relvema.com.
Patient data is retained as long as the therapist-patient connection is active. Therapists can disconnect a patient at any time, which removes that patient’s data from the therapist’s view.
Account deletion removes all associated therapist records, connections, and session mirrors from the therapist database. Patient-side data in the primary database follows the mobile app’s deletion policy, as it is owned by the patient.
To request full data deletion, contact support@relvema.com. We will complete the request within 30 days.
In the event of a breach involving unsecured PHI, Relvema will notify affected covered entities within 60 days of discovery, as required by the HIPAA Breach Notification Rule.
Google Cloud’s infrastructure includes automated threat detection, audit logging, and intrusion monitoring. All access to production systems is logged and reviewed.
To report a potential security incident, email security@relvema.com immediately.
Our team can walk you through how Relvema fits into your practice’s compliance framework and provide a signed BAA if required. Reach us at support@relvema.com.