security & privacy

Serious security. Stated honestly.

Behavioral-health data deserves more care than generic SaaS gives it. Here\u2019s exactly how Better is protected — including what we are, and aren\u2019t yet, certified for.

Built by a security engineer, run as one system.Better\u2019s Founder & Technology Officer spent his career on high-security enterprise systems. Security here isn\u2019t a feature bolted on later — it\u2019s the foundation, and it\u2019s one person\u2019s explicit job.

HIPAA, with a BAA

Better is built for HIPAA\u2019s privacy and security requirements from the ground up, and we sign a Business Associate Agreement with every practice. Down the stack, every vendor that could touch protected health information operates under a signed BAA with us — including our clearinghouse (claims), our telehealth infrastructure, and Google Cloud.

Our environment — wholly ours

Better runs in a Google Cloud environment that we wholly control — our project, our keys, our access policies. No shared multi-vendor sprawl: one environment, one accountable owner, covered by Google Cloud\u2019s BAA.

SOC 2- and HITRUST-aligned controls — stated honestly

We operate the control families that SOC 2 and HITRUST audits examine. We are not yet certified — formal SOC 2 attestation is planned as we scale, and we\u2019d rather tell you that plainly than imply a badge we don\u2019t hold. What we practice today:

Access control & least privilege
Role-based access, unique accounts, MFA on administrative access, and reviews of who can touch what.
Encryption
Data encrypted in transit and at rest across the platform.
Audit logging
Immutable audit trails on the actions that matter — gateway overrides, credential changes, consent timestamps — so you can show your work.
Change management
Code review, staged deploys, and rollback paths — changes don’t go straight to your charts.
Monitoring & incident response
Logging and alerting on the environment, with a documented response process.
Vendor management
Every subprocessor that could touch PHI operates under a signed BAA (see below).
Data retention & disposal
Plain-English retention windows; tenant-scoped deletion and export.
Business continuity
Managed, replicated infrastructure with backups — your records don’t live on someone’s laptop.

Your data stays yours

Tenant-scoped export of your full record set, anytime, at no cost — the No-Hostage Guarantee. Privacy mode masks client names on-screen for shared spaces. And there is no AI touching your clinical data — see the AI Standard.

This page is reviewed by Better\u2019s Security Officer; report security concerns to hello@betterehr.com.

Book a demoMore on this page is coming together — talk to us in the meantime.