How we protect your patient data.
Staid is HIPAA-grade software. We use a small, deliberate set of infrastructure partners — each chosen for the sensitivity of behavioral-health data. Here’s exactly who has access to what, and why.
Stedi
Insurance claim clearinghouseSigned Business Associate Agreement (BAA)What they seeThe claim itself — codes, charges, dates of service — and the patient identifiers payers need to process it (name, date of birth, insurance ID). No clinical notes.
Why we use themBuilt specifically for healthcare claims; provides the EDI infrastructure required to submit 837P claims and receive 835 remittances reliably.
Supabase
Database where your patient records and notes liveSigned Business Associate Agreement (BAA)What they seeThe records and notes you create in Staid. Data is encrypted at rest, and row-level security keeps each practice’s records isolated from every other account.
Why we use themHealthcare-ready Postgres with row-level security, encryption at rest, and a Business Associate Agreement available out of the box.
OpenAI
Transcribes session audio into textSigned Business Associate Agreement (BAA)What they seeThe session audio you record. The audio is transcribed and then deleted on the schedule you set — by default, immediately after transcription.
Why we use themWhisper is the most accurate speech-to-text model for clinical language, and OpenAI offers a HIPAA-compliant business tier with zero data retention.
Anthropic
AI that helps draft claims and appeal letters from your notesSigned Business Associate Agreement (BAA)What they seeThe structured note text used to draft a claim or an appeal letter. No audio. No data is used to train models.
Why we use themClaude is the model best suited to careful, structured clinical writing, and Anthropic offers a zero-retention, HIPAA-compliant tier.
Resend
Sends emails to your patients (invoices, reminders)Signed Business Associate Agreement (BAA)What they seeThe patient’s email address and the body of the message — typically an invoice or appointment reminder you’ve approved.
Why we use themReliable transactional email built for product workflows, with a security posture and BAA process appropriate for HIPAA contexts.
Vercel
Hosts the Staid web applicationSigned Business Associate Agreement (BAA)What they seeThe hosting layer that serves the Staid app to your browser. Patient records are not stored on Vercel — those live in Supabase.
Why we use themBest-in-class hosting for Next.js with global edge delivery, and a Business Associate Agreement available for healthcare customers.
Stripe
Processes patient credit card paymentsSigned Business Associate Agreement (BAA)What they seeThe card details that the patient enters at the time of payment. Card numbers never touch Staid’s servers.
Why we use themThe PCI-compliant payment processor most trusted across healthcare; carries the certifications a clearinghouse expects.
Coming soon
We’ll add the privacy details for these partners before launching the features they support.
- Video sessions: Daily.co
- SMS reminders: Twilio
We update this page whenever a vendor changes. Last updated: June 23, 2026.
Questions? Email support@staidhealth.com.