The safeguards protecting your evaluation data
HIPAA does not simply require that health information be kept private — it requires demonstrable safeguards across three categories. Here is what each category means in practice for an ESA or PSD evaluation.
Three categories, one system
Administrative, physical and technical safeguards
The Security Rule splits protection into three categories. A system that is strong in one and weak in another is not compliant — the categories are cumulative, not alternatives.
Who is allowed near your data, and why
Access follows least privilege: staff can reach only what their role requires. Permissions are reviewed, training is mandatory and repeated, and every vendor touching protected health information operates under a written business associate agreement that binds them to the same standard.
Where the data physically lives
Records are held in access-controlled data centre environments rather than on local machines. Workstation controls, screen locks and device policies limit what can be seen or extracted, and disposal of any media follows a documented destruction process.
What the systems themselves enforce
Transport is encrypted in transit and data is encrypted at rest. Authentication is enforced for every account, sessions expire, and audit logs record access so that unusual patterns can be investigated after the fact as well as blocked in the moment.
Audit trails
Why logging matters more than encryption
Encryption gets the attention, but the safeguard that most often detects a real problem is the audit log. Encryption stops an outsider reading data they have intercepted. Logging is what reveals an insider looking at a record they had no business opening.
Access records are retained so that a specific question — who opened this file, and when — can be answered rather than estimated. That capability is also what makes the accounting of disclosures right meaningful in practice.
The part of the system you control
Your own account
A unique password not reused elsewhere, and two-factor authentication where offered, closes the most commonly exploited gap in any health system.
Your email
Documents delivered to a shared or work mailbox are outside our safeguards the moment they arrive. Use an address only you can read.
Your onward sharing
Once you forward a letter to a landlord, its protection depends on what they do with it. Send it to a named person, not a general inbox, where you can.
Frequently asked
Is my ESA evaluation data encrypted?
Yes, both in transit between your browser and the service and at rest in storage. Encryption is one of several required technical safeguards rather than the whole of the protection.
Who inside the service can see my file?
Access follows least privilege. The reviewing clinician sees the clinical content; a limited number of administrative staff can reach what their role requires for scheduling, delivery and verification.
Are third-party vendors allowed to touch my data?
Only under a written business associate agreement that binds them to equivalent safeguards. A vendor without that agreement in place should not be handling protected health information at all.
Can I ask who has accessed my record?
Yes. Access is logged, and you can request an accounting of certain disclosures. Logging is what makes that right answerable rather than theoretical.
What happens to my data if I never complete the evaluation?
An incomplete intake is still treated as protected health information and held under the same safeguards, subject to the applicable retention schedule.
Does using a public Wi-Fi network put my evaluation at risk?
Traffic between your browser and the service is encrypted, so interception on an open network does not expose the content. The larger risk on a shared network is an unlocked screen or a saved session on a device others can reach.
Your privacy is not an afterthought here
Start a free evaluation and see exactly what your landlord will — and will not — receive.
Start free evaluation All privacy topics