CareCompass · Policy Center

HIPAA & Health-Data Notice

Effective
July 12, 2026
Last updated
July 12, 2026
Version
2026-07-12-v1

CareCompass is a software service operated by Mindful Me, LLC. These policies are the current published version. Questions? Contact andrea@andreagoundrycounseling.com.

Beta rules, please read.

  • CareCompass is not HIPAA compliant during the current clinician beta.
  • Mindful Me, LLC is still completing HIPAA-readiness work.
  • No CareCompass Business Associate Agreement (BAA) is currently available.
  • You must not enter protected health information (PHI) or client-identifying information into CareCompass.
  • This prohibition applies regardless of client or guardian consent.
  • The prohibition includes AI prompts, notes, check-ins, roadmaps, summaries, feedback, uploads, and all other fields.
  • Use client initials, non-identifying labels, demonstration data, or properly de-identified information only.

CareCompass is a software service operated by Mindful Me, LLC. This notice describes CareCompass's current HIPAA-readiness status and the rules clinicians must follow while the service is in beta.

1. What CareCompass currently is, and is not

CareCompass is a collaboration and organizational tool for clinicians. In its current clinician-beta form, CareCompass has not been verified as HIPAA compliant. Vague language such as "HIPAA-friendly" or "HIPAA-ready" should not be interpreted as certification, attestation, or a substitute for a signed BAA.

2. Current CareCompass security measures

The following controls are in place today and are described here so clinicians can assess CareCompass on its actual controls, not on aspirational language:

  • encryption in transit (HTTPS) for all traffic;
  • row-level security enforcing per-user access to data;
  • multi-factor authentication (MFA) for clinicians, with server-side assurance-level checks;
  • trusted-device controls;
  • server-side authorization for privileged operations, including policy-acceptance recording and subscription creation;
  • audit logging of administrative and sensitive actions;
  • role separation between the administrative Owner role and clinician access;
  • payment processing delegated to Stripe so CareCompass never receives or stores full card numbers.

No system can be guaranteed absolutely secure, and these controls do not, on their own, make CareCompass HIPAA compliant.

3. HIPAA-readiness work in progress

Mindful Me, LLC is working toward the operational, administrative, and contractual requirements needed to responsibly support PHI. Until that work is complete and the BAA process below is operational, clinicians must treat CareCompass as a non-PHI environment.

4. BAA status

A Business Associate Agreement between Mindful Me, LLC and clinicians is not presently available. Nothing on this page, and no template text that may appear here in the future, constitutes an executed BAA. When BAAs become available, we will announce the process directly to clinicians and update this notice with an effective date.

Availability of a CareCompass BAA is also contingent on Mindful Me, LLC confirming that all relevant subprocessors listed in the Privacy Policy have BAAs in place where PHI would flow.

5. Clinician responsibilities

Your obligations under HIPAA, state law, and your professional licensure are independent of CareCompass. You remain responsible for:

  • determining what constitutes PHI in your practice and keeping it out of CareCompass during beta, including out of AI prompts;
  • obtaining any authorizations, consents, or releases from clients and, for minors, guardians before using CareCompass to organize information about them, even in de-identified form, noting that such consent does not override the current beta prohibition on entering PHI or client-identifying information;
  • practicing data minimization, enter only what you actually need for clinical organization; and
  • maintaining your own privacy and security safeguards for your practice, including for any records you keep outside CareCompass.

6. No emergency use, crisis vs. immediate danger

CareCompass is not an emergency-response service and does not monitor entries in real time. Entering information into CareCompass does not contact a clinician, crisis responder, emergency service, or law-enforcement agency.

  • For mental-health crisis support in the United States, call or text 988 (Suicide and Crisis Lifeline).
  • For immediate danger or a medical emergency, call 911. 988 is a crisis support line, not a substitute for emergency services when someone is in immediate danger.

7. Breach and security contact

If you believe your CareCompass account has been compromised, or you suspect a data-security issue, contact CareCompass immediately at andrea@andreagoundrycounseling.com with the subject line "Security." Include only the information necessary to describe the issue; do not include client-identifying information.

8. Notifications

When PHI use becomes permitted and BAAs are operational, CareCompass will notify clinicians by email and in-app announcement, and this notice will be updated with an effective date and version.

9. Contact

Questions about this notice or the HIPAA-readiness work? Contact andrea@andreagoundrycounseling.com.