Security

How we protect your patient data.

Staid is HIPAA-grade software. We use a small, deliberate set of infrastructure partners — each chosen for the sensitivity of behavioral-health data. Here’s exactly who has access to what, and why.

  • Stedi

    Insurance claim clearinghouse
    What they see

    The claim itself — codes, charges, dates of service — and the patient identifiers payers need to process it (name, date of birth, insurance ID). No clinical notes.

    Why we use them

    Built specifically for healthcare claims; provides the EDI infrastructure required to submit 837P claims and receive 835 remittances reliably.

    Signed Business Associate Agreement (BAA)
  • Supabase

    Database where your patient records and notes live
    What they see

    The records and notes you create in Staid. Data is encrypted at rest, and row-level security keeps each practice’s records isolated from every other account.

    Why we use them

    Healthcare-ready Postgres with row-level security, encryption at rest, and a Business Associate Agreement available out of the box.

    Signed Business Associate Agreement (BAA)
  • OpenAI

    Transcribes session audio into text
    What they see

    The session audio you record. The audio is transcribed and then deleted on the schedule you set — by default, immediately after transcription.

    Why we use them

    Whisper is the most accurate speech-to-text model for clinical language, and OpenAI offers a HIPAA-compliant business tier with zero data retention.

    Signed Business Associate Agreement (BAA)
  • Anthropic

    AI that helps draft claims and appeal letters from your notes
    What they see

    The structured note text used to draft a claim or an appeal letter. No audio. No data is used to train models.

    Why we use them

    Claude is the model best suited to careful, structured clinical writing, and Anthropic offers a zero-retention, HIPAA-compliant tier.

    Signed Business Associate Agreement (BAA)
  • Resend

    Sends emails to your patients (invoices, reminders)
    What they see

    The patient’s email address and the body of the message — typically an invoice or appointment reminder you’ve approved.

    Why we use them

    Reliable transactional email built for product workflows, with a security posture and BAA process appropriate for HIPAA contexts.

    Signed Business Associate Agreement (BAA)
  • Vercel

    Hosts the Staid web application
    What they see

    The hosting layer that serves the Staid app to your browser. Patient records are not stored on Vercel — those live in Supabase.

    Why we use them

    Best-in-class hosting for Next.js with global edge delivery, and a Business Associate Agreement available for healthcare customers.

    Signed Business Associate Agreement (BAA)
  • Stripe

    Processes patient credit card payments
    What they see

    The card details that the patient enters at the time of payment. Card numbers never touch Staid’s servers.

    Why we use them

    The PCI-compliant payment processor most trusted across healthcare; carries the certifications a clearinghouse expects.

    Signed Business Associate Agreement (BAA)

Coming soon

We’ll add the privacy details for these partners before launching the features they support.

  • Video sessions: Daily.co
  • SMS reminders: Twilio

We update this page whenever a vendor changes. Last updated: June 23, 2026.
Questions? Email support@staidhealth.com.