StreamABA Back to Home

HIPAA Notice of Privacy Practices

Last Updated: September 17, 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Introduction

STREAM ABA LLC ("Stream ABA," "we," "us," or "our") provides a cloud-based practice management platform for Applied Behavior Analysis (ABA) therapy practices. In providing our services, we may receive, maintain, and transmit Protected Health Information (PHI) on behalf of healthcare providers who use our platform.

This Notice of Privacy Practices ("Notice") explains how Stream ABA, acting as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), protects, uses, and discloses PHI.

Our Commitment to Privacy

We are committed to protecting the privacy and security of PHI. We are required by law to:

  • Maintain the privacy and security of PHI
  • Provide you with this Notice of our legal duties and privacy practices
  • Follow the terms of this Notice currently in effect
  • Notify affected individuals following a breach of unsecured PHI

Understanding Your Health Information

When ABA therapy practices use our Service, they may enter information about their clients, including:

  • Client demographics and contact information
  • Diagnosis, intake, and clinical documentation
  • Clinical goals and programming data
  • Session notes and progress data
  • Behavior data and clinical observations
  • Insurance and billing information
  • Authorization records

This information is considered Protected Health Information (PHI) under HIPAA.

How We May Use and Disclose PHI

As a Business Associate, we use and disclose PHI only as permitted by our Business Associate Agreements with Covered Entities and as allowed by HIPAA. The following describes the ways we may use or disclose PHI:

For Treatment

We enable healthcare providers to use our platform to document and coordinate client care, including creating recording session data, and tracking progress toward goals.

For Payment

We support billing activities, including generating claims, tracking authorizations, and managing payment information to facilitate reimbursement for services.

For Healthcare Operations

We support operational activities such as quality improvement, staff scheduling, reporting, and practice management.

As Required by Law

We may disclose PHI when required by federal, state, or local law, including for public health activities, to report abuse or neglect, or in response to court orders.

To Avert Serious Threat

We may use or disclose PHI when necessary to prevent a serious threat to health or safety.

For Business Associate Functions

We perform services for Covered Entities that require access to PHI, such as data hosting, technical support, and data analytics.

Uses and Disclosures Requiring Authorization

We will not use or disclose PHI for purposes other than those described in this Notice without written authorization from the Covered Entity or, where applicable, the individual. Uses requiring authorization include:

  • Marketing purposes
  • Sale of PHI
  • Most uses of psychotherapy notes (if applicable)
  • Other purposes not described in this Notice

Authorizations may be revoked at any time in writing, except to the extent we have already acted in reliance upon the authorization.

Your Rights Regarding PHI

HIPAA provides individuals with certain rights regarding their PHI. As a Business Associate, we support Covered Entities in honoring these rights. If you are a client of an ABA practice using Stream ABA, you should contact your healthcare provider directly to exercise these rights:

Right to Access

You have the right to inspect and obtain a copy of PHI maintained about you. Your healthcare provider may charge a reasonable fee for copies.

Right to Request Amendment

You have the right to request that your healthcare provider amend PHI they maintain about you if you believe it is incorrect or incomplete.

Right to an Accounting of Disclosures

You have the right to request a list of certain disclosures of your PHI made by your healthcare provider.

Right to Request Restrictions

You have the right to request restrictions on how your healthcare provider uses or discloses your PHI for treatment, payment, or healthcare operations.

Right to Request Confidential Communications

You have the right to request that your healthcare provider communicate with you about your PHI in a certain way or at a certain location.

Right to a Paper Copy of This Notice

You have the right to obtain a paper copy of this Notice upon request.

Our Duties

We are required to:

  • Maintain the privacy and security of PHI
  • Provide notice of our legal duties and privacy practices
  • Abide by the terms of this Notice
  • Notify Covered Entities of breaches of unsecured PHI
  • Not use or disclose PHI except as described in this Notice or as authorized

Security Measures

We implement comprehensive administrative, physical, and technical safeguards to protect PHI, including:

  • Encryption: All PHI is encrypted in transit and at rest using industry-standard encryption (TLS 1.2+ and AES-256)
  • Access Controls: Role-based access controls limit PHI access to authorized personnel
  • Audit Logs: We maintain comprehensive audit logs of system access and PHI usage
  • Employee Training: All employees receive HIPAA training and sign confidentiality agreements
  • Incident Response: We maintain incident response procedures for security events
  • Regular Assessments: We conduct regular security risk assessments and penetration testing
  • Data Center Security: Our infrastructure is hosted in SOC 2 compliant data centers

Breach Notification

In the event of a breach of unsecured PHI, we will:

  • Notify the affected Covered Entity without unreasonable delay and no later than 60 days after discovery
  • Provide information necessary for the Covered Entity to notify affected individuals
  • Cooperate with the Covered Entity's breach investigation and notification obligations
  • Document the breach and our response

Complaints

If you believe your privacy rights have been violated, you may:

File a Complaint with Your Healthcare Provider

Contact the ABA practice that provides your care. They are responsible for the PHI they maintain about you.

File a Complaint with Stream ABA

Contact us at the address below if you have concerns about how we handle PHI as a Business Associate.

File a Complaint with the U.S. Department of Health and Human Services

You may file a complaint with the Secretary of Health and Human Services. Information about how to file a complaint is available at www.hhs.gov/hipaa/filing-a-complaint.

You will not be retaliated against for filing a complaint.

Changes to This Notice

We reserve the right to change this Notice and make the revised Notice effective for PHI we already have as well as any PHI we receive in the future. The current Notice will be posted on our website with its effective date.

Business Associate Agreements

If you are a healthcare provider considering using Stream ABA, you must enter into a Business Associate Agreement (BAA) with us before entering any PHI into our Service. Please see our Business Associate Agreement page for more information.

Contact Information

For questions about this Notice or our privacy practices:

STREAM ABA LLC

Privacy Officer

Email: [email protected]

Website: streamaba.com

For questions about the privacy of your health information as a client of an ABA practice, please contact your healthcare provider directly.

Effective Date

This Notice is effective as of September 17, 2026.

Privacy Policy Terms of Service HIPAA Notice Acceptable Use SMS Consent

© 2026 StreamABA LLC. All rights reserved.