Security Trusted by 15,000+ Providers
and 20+ Government Agencies
Documentation in human services holds some of the most sensitive information there is: diagnoses, medication records, incident reports, and daily notes about people's lives. Therap has protected that information for more than 20 years, for provider agencies of every size and for state and local governments. Therap’s HIPAA compliant system ensures your data is secure and accessible, while giving you control over user access.
How Therap Safeguards Your Data
Built for Leading Security Requirements
Therap meets HIPAA and HITECH requirements, along with FERPA, ARC‑AMPE, and federal accessibility standards.
Independently Audited Every Year
Therap undergoes annual third‑party SOC 2 Type II assessments covering security, availability, processing integrity, confidentiality, and privacy.
Encrypted in Transit and at Rest
Your data is encrypted across all database components, unstructured files, and off‑site backup tapes.
Consistently Available
Therap runs from multiple secure, geographically separated facilities in the United States, with data continuously replicated between them.
Therap Puts You in Control of Data Access
Permissions and Caseloads
Grant staff only the access their role requires, and limit them to the individuals they actually support.
Activity Tracking
See date, time, and location‑stamped records of what your staff did in the system, so audits and investigations start with answers rather than questions.
Your Password Rules
Configure password requirements to match your organization's policies, and turn on two‑factor authentication for added protection.
Therap Ratings and Reviews
Frequently Asked Questions
Is Therap HIPAA compliant?
Yes. Therap meets HIPAA and HITECH requirements. Data is encrypted, every record view and edit is logged, and access is controlled by permissions the accountable organization sets.
Is the data we store in Therap encrypted?
Yes, both while stored and while in transit, including backups.
Can staff document from their phones without putting data at risk?
Yes. Therap's mobile app lets staff document at the point of care without storing Protected Health Information on the device, and inactive sessions close automatically.
Our state or funder sent us a security questionnaire. Can you help?
Yes. Therap works with agencies going through security reviews regularly and can provide the documentation you need.
How does Therap keep one provider's data separate from another's within a state deployment?
Each provider organization maintains its own account and its own records. State oversight users receive access scoped to their role and jurisdiction, so a state team can see across the network without providers gaining visibility into one another.
What security certifications does Therap maintain?
Therap completes an annual independent SOC 2 Type II assessment covering security, availability, processing integrity, confidentiality, and privacy, and is hosted in ISO 27001‑certified data centers.
Where is the data we have in Therap stored?
In certified, secure data centers in the United States, across multiple geographically separated locations so information stays available if one site goes offline.
How can providers control which staff see which records?
Your administrators assign permissions by role and limit access to specific individuals through caseload assignment. You can also set your own password requirements and enable two‑factor authentication.
Does Therap meet federal accessibility requirements?
Yes. Therap meets Section 508, ADA Title II, and WCAG 2.2.
Can we review Therap's security documentation as part of our procurement process?
Yes. Therap is able to share additional information regarding our security upon request. Please reach out to your Therap representative for more details.