Guidelines›Security›United States

United States · HIPAA · HITECH · 42 CFR Part 2 · 45 CFR Parts 160 and 164

Everything the United States asks of a clinic, and what the software does about it.

This is the complete United States page. It covers every rule that applies to a mental-health practice here, says in plain words what each one asks for, and shows what has been built to answer it. The last part is the one most documents leave out: the actual step-by-step flows that run inside the software — what a member of staff sees, what the system checks, and where it refuses.

You do not need any technical knowledge to read it. Where a regulation is named, the sentence next to it says what that regulation actually wants in ordinary language. Nothing here assumes you have opened the software.

Privacy and security officers Practice managers Clinical directors Buyers running due diligence Counsel
4HIPAA rules covered 8 / 8technical safeguards 7flows walked through 6 yrsof disclosures on demand 521automated tests passing
01 — Orientation

Six sets of rules, and what each one is actually about

People say "HIPAA" as if it were one rule. It is an act with several rules under it, and they ask for different things. A system can be strong on one and absent on another, which is why it is worth separating them before looking at any software at all.

Here is each one in a sentence, followed by where this platform stands on it.

45 CFR 164 Subpart E

The Privacy Rule

What it is about: who may see health information, what a patient may ask for, and what has to be written down when information is shared. This is where the patient's rights live — a copy of their record, a correction, a restriction, and a list of who their information went to.

Where we stand: built, including the parts most systems leave out — the extension on a request, cost-based fees, the format the patient asked for, sending a copy to somebody they nominate, and what happens after a correction is refused.

45 CFR 164 Subpart C

The Security Rule

What it is about: how electronic health information is protected. It has three parts — technical (what the software does), administrative (what the organisation does), and physical (where the equipment is and who can touch it).

Where we stand: all eight technical safeguards built. The administrative programme has records for every part of it. The physical safeguards are registers for buildings, workstations and devices — because two of those four standards are about records, not locks.

45 CFR 164 Subpart D

The Breach Notification Rule

What it is about: what you must do after health information is exposed. Assess it against four factors, tell the people affected within 60 days, tell the media if more than 500 residents of one state are involved, and tell the federal health department.

Where we stand: built, with all of the above plus the two clocks that run when a supplier is the one who discovers it, and the rule that a phone call from law enforcement only delays you for 30 days.

HITECH Act · 2009

HITECH

What it is about: a later act that strengthened HIPAA. It is why breach notification exists at all, why suppliers are directly liable, and why a patient who pays for their own care in full can insist it is not reported to their insurer.

Where we stand: built. That self-pay restriction is the interesting one — the software will not let staff turn it down, because the act does not give them the choice.

42 CFR Part 2

Substance-use treatment records

What it is about: a separate federal rule, stricter than HIPAA, for records from federally assisted substance-use treatment. Anything shared has to carry a notice forbidding the recipient from passing it on.

Where we stand: built, including the 2024 changes — the single consent covering treatment, payment and operations, restrictions that understand Part 2, and Part 2 breaches running through the HIPAA process.

State law

Your own state, on top of all of it

What it is about: HIPAA is a floor, not a ceiling. California's CMIA, and rules in New York, Texas and elsewhere, go further — often on retention periods and on what a minor can consent to themselves.

Where we stand: the settings are per company, so a stricter state rule can be configured rather than argued with. What the setting should be is a question for your counsel, and this is the one item on this page that no software can answer for you.

02 — The whole list

Everything HIPAA asks of a practice, and what we do about each one

This is the complete list, in ordinary words. Every row is something the law asks of your practice, and beside it is what the software does about it — in one sentence, without jargon.

If you only read one section of this page, read this one. Everything after it is the same material in more depth, for whoever has to check the detail.

✓The software does itBuilt and working. You can be shown it on a live system. ⚙The software does it, you set the numbersThe machinery is there. How long, how strict, and who — those are yours. ◐Partly thereSomething real is still missing, and section 11 says exactly what. §Not something software can doIt is about your building, your people or your paperwork. Section 12.

Patients' rights over their own records

What the law asksWhat we do
Give patients a privacy notice✓The notice is kept as a dated version, and when a patient signs for it we record which version they actually saw — not just that they signed something.
Let a patient see and get a copy of their record✓The request is a job with a name on it and a deadline the system works out. Nobody types the date, so nobody types the wrong one.
Give it to them in the form they asked for✓If you could not produce what they asked for, the request will not close until what you agreed instead is written down.
Charge no more than a reasonable fee✓Only the four costs the law allows can be entered. There is nowhere to type the extras that usually cause the fine.
Let a patient ask you to correct their record✓A correction never overwrites the original — it adds a new version. The old one stays readable, which is what makes a record evidence.
If you refuse a correction, let them file a disagreement✓Their statement travels with the record from then on, and anything you send out afterwards carries it too. A refusal does not end the matter.
Tell a patient who you shared their record with✓Every disclosure is recorded when it happens, so the six-year history is already there when somebody asks for it.
Honour a request to be contacted differently✓If a patient says do not call this number, the system will not use it — and if the only allowed way of reaching them is blocked, the message fails loudly rather than quietly falling back to the number they asked you not to use.
Honour a request to restrict sharing✓Including the one restriction you cannot refuse — where a patient pays privately and asks you not to tell their insurer.
Only use or share the minimum needed✓A disclosure cannot be saved without a note saying why no more than necessary went out.
Handle complaints about privacy✓A complaint is a record with an owner and an outcome. It cannot be closed without saying what happened.
Never retaliate against someone who complains✓Recorded against the complaint, so the file shows it was considered.
Keep therapy process notes separate✓The strongest thing on this page. They are locked with a different key, kept out of what a records request produces, and a note cannot be quietly moved into the ordinary record later.
Know who may act for a patient◐We can record that a parent or guardian signed something. We cannot yet record that a named person may read a patient's record — see section 11.

Keeping the records safe — what the software must do

What the law asksWhat we do
Everyone has their own login✓Shared logins are not supported. The moment two people share an account, the record of who did what stops meaning anything.
Scramble the records so a stolen copy is useless✓Every document version gets its own key, and the master key is kept outside the database — so a stolen database is a pile of noise.
Keep a record of who looked at what✓Written before the record opens, and linked together so a removed entry shows up as a gap. Not even your own administrator can quietly edit it.
Make sure records have not been altered✓Every version carries a fingerprint that is checked each time it is opened.
Screens lock themselves when left alone✓Enforced by the server, so it cannot be switched off in a browser. You choose the number of minutes; it warns first so nobody loses a half-written note.
A way in during a real emergency✓A clinician can reach a record they have no relationship with — and it is recorded as an event and reviewed afterwards. A system that only ever blocks fails this rule too.
Protect records travelling over the network✓Encrypted in transit, and the system checks its own connection settings and keeps the result as evidence rather than as an assurance.
Confirm people are who they say they are✓Two-step verification can be required before anyone opens a record. Start on warn only: access does not change and the system records exactly who still needs enrolling, so you switch it on from a list rather than a guess. Emergency access is deliberately exempt — a lost or flat phone is precisely the situation it exists for.

Running the practice — what has to be written down

What the law asksWhat we do
Assess your risks, in writing✓Risks are records, not a document — each one naming what could go wrong, how likely it is, how bad it would be, and what is left after you have dealt with it.
Actually reduce the risks you found✓An untreated serious risk is a number on the front of the assessment, not a line somebody has to notice.
Review your access logs regularly✓A dated review with a named reviewer, the questions actually asked, and anything found — plus a check that the log itself has not been tampered with.
Re-check the whole thing periodically✓A separate evaluation covering both the technical side and whether your written policies still describe what the practice really does — which is the half usually skipped.
Name a security officer and a privacy officer✓Appointments with start and end dates, and the system notices when a role has quietly become vacant.
Give people only the access they need✓Access follows the treatment relationship, not the job title — and it ends when the relationship does. Being an administrator opens no clinical record by itself.
Review who has access, and keep it current✓Each grant has a review date, and the system flags where someone's real access has drifted away from what was approved.
Remove access when someone leaves✓A six-step checklist — including ending their treatment relationships, the step everybody forgets because it is the one that actually grants access.
Train your staff⚙Training records with expiry dates. The training itself is yours to deliver.
Discipline staff who break the rules✓A sanction record naming the policy, what was done and who decided.
Have a plan for fire, flood or ransomware✓Plans list each system with how fast it must come back and how much data you could afford to lose — and a target the plan cannot actually meet is a named field, not an optimistic assumption.
Test that plan✓Tests are records. A plan that has never been tested looks different from one that has, which is the entire point.
Back up the records§This one is yours. The system describes what the backup must achieve; it cannot take it for you. Section 12.
Keep written agreements with your suppliers✓A register with each agreement's dates and the three promises the law requires, so a half-signed relationship is visible instead of assumed.
Keep your policies current, and keep them six years✓Every policy is versioned with its own dates, and old versions are never overwritten.

The building, the desks and the devices

What the law asksWhat we do
Control who can physically get to the systems⚙These are about doors and rooms, so what the software holds is the register that proves you did them — with an owner and a review date. That register is what an assessor asks for.
Say what each workstation is for, and secure it⚙Same — recorded, with an owner.
Dispose of records and old equipment properly✓This one is genuinely ours. Disposing of a record destroys its key, so the content is unreadable even from an old backup — while the proof that you disposed of it survives. Deleting a row can be undone; this cannot.

When information gets out

What the law asksWhat we do
Assume it is a breach unless you can show otherwise✓The four questions the law asks are four things you must answer. The record will not close as "not a breach" with nothing written in it — an answer with no reasoning is the one a regulator disbelieves.
Encrypted information may not be a breach at all✓Because every record is encrypted with its own key, "could anyone actually read it?" has a real answer rather than a hopeful one.
Tell affected patients within 60 days✓The deadline appears by itself, counted from the day you found out.
Say the five things the notice must say✓Including what the patient should do about it — the part most often written badly, and the only part they act on.
Tell the media if 500 people in one state are affected✓Counted per state, not on the total — the sum most systems get wrong.
Tell the regulator✓Straight away for large breaches; for small ones an annual list, built automatically — the deadline nobody remembers because it comes round once a year.
Let law enforcement delay the notice✓A written request runs for the period it states. A spoken one expires by itself after thirty days unless it is put in writing — the trap in the rule, handled for you.
Be able to prove you did all this✓It is one linked file from the first suspicion to the last letter — rather than something assembled afterwards out of three mailboxes.

Substance-use records — the stricter rules

What the law asksWhat we do
Give patients a separate confidentiality notice✓Its own notice, versioned and acknowledged the same way as the main one.
Attach a warning to every disclosure✓The warning that the recipient may not pass it on is produced by the system, not typed by a person, so it cannot be forgotten on a busy day.
These records may not be used against the patient✓Stated in the notice the patient receives.
The honest summary, in one paragraph

Of everything HIPAA asks, the software carries the great majority of it outright, a handful are yours to set a number on, and two are genuinely unfinished — refusing a login without two-step verification, and recording who may act for a patient. Both are named in section 11 rather than left for you to discover. A few things are not software's job at all — your backups, your building, your training — and those are in section 12. No product can make a practice HIPAA compliant. What this one does is carry your copy of the obligation, and hold the evidence that you met it.

03 — The Privacy Rule

Each patient right, and what carries it

Read the middle column first. The right-hand column says what it actually does, in ordinary words. The code numbers are there so a reviewer can check them; you can ignore them entirely and the sentence still makes sense.

Four marks are used in every table on this page, and the difference between the middle two matters. One means something is missing. The other means nothing is missing and a decision is yours to make.

✓BuiltIn the software now. Somebody can be shown it working. ⚙Built — you set the valueNothing is missing. The number or the answer is a decision for your practice, and the row says which decision. ◐Partly builtSomething is genuinely missing. The row says exactly what, so it can be planned around. —Not builtListed in section 10 rather than left to be discovered.
What the rule asks forStatusWhat is built
The patient can ask for a copy of their record164.524 ✓ A tracked request with a deadline the system works out for itself, and a decision at the end. Complete with the five parts that generate most of the federal enforcement: one extension of up to thirty days, which records both the reason and the date the patient was actually told; an itemised fee limited to the four things the rule permits, with a warning when it goes over your configured cap; the format they asked for; sending a copy to somebody they nominate, linked to their written instruction; and review of a refusal by a named professional who was not part of the original decision.
They can ask for something to be corrected164.526 ✓ A correction is filed as a new version — the original is never overwritten. Complete through what happens when a correction is refused: the patient's statement of disagreement in their own words, the clinic's written reply, and the rule that both must travel with any future sharing of that record. The system attaches them automatically, so it does not depend on anyone remembering.
They can ask you to restrict something164.522(a) ✓ A restriction seals the documents it covers and records the reason and the decision. Lifting it puts the document back to the sensitivity it had before, not to "ordinary". It includes the self-pay restriction: where the patient paid in full themselves, the software refuses to let staff turn the request down at all, because HITECH does not give them that choice.
They can ask to be contacted differently164.522(b) ✓ "Do not call my home. Write to this address." In a mental-health service this is not administration — it is the mechanism by which a service avoids revealing to an abusive partner or relative that somebody is in therapy. The request, the decision and the binding of that decision to every outgoing message are all built.
They can ask who their information went to164.528 ✓ A register of what left the service, to whom, on what basis and when — reportable for six years, produced on demand rather than assembled by hand. It gathers from every register in the system, which matters: there is more than one, and an answer drawn from only one of them would hand a patient six disclosures out of eight with nothing to suggest anything was missing.
Family and friends can be told — unless the patient objects164.510 ✓ The rule gives four different bases for telling somebody involved in a patient's care, and they stay four rather than collapsing into a "family may be told" tick box — because the question afterwards is never whether somebody was told, it is on what basis. An objection is enforced, not displayed: the software refuses to record a disclosure to a person the patient objected to.
You must give them a privacy notice164.520 ✓ The notice is a versioned document with an effective date. Receipt is acknowledged and recorded — and where the patient will not sign, the good-faith effort and the reason it failed are recorded too, which is what the rule actually requires. A material change creates a new version rather than editing the old one.
They can complain, and you must record it164.530(d) ✓ A complaint cannot be closed without both an outcome and the reasoning behind it. "No action" is a permitted outcome — the rule says the disposition may be nothing, not that it may be unrecorded. Complaints cannot be deleted.
Written authorisation where it is needed164.508 ✓ Signed authorisations are held in the e-signature module, and a disclosure that claims to rest on one is refused unless it names the authorisation it relies on. That turns "we had consent" from somebody's memory into a link.
Only what is needed for the job164.502(b) ◐ Built: staff reach the records of the people on their own caseload rather than the clinic's, because access follows the care relationship and not the job title. On the sharing path, the purposes the rule exempts and the judgement that was made are both recorded.

What remains: that judgement is recorded rather than applied automatically at every route. A person still decides how much to send; the system captures the decision instead of making it. Closing this would mean the software deciding "minimum necessary" on your behalf, and any product claiming to do that is overstating what software can do — so expect to show a policy and a record here, not an algorithm.
Fix the damage when something goes wrong164.530(f) ✓ A mitigation record: what harm was done, what was done about it, by whom and when. Separate from the breach record, because most things that need mitigating are not breaches.
Deciding data is no longer identifiable164.514 ✓ The system records the determination; it does not make it. The eighteen identifiers are eighteen separate answers, because the claim fails on the one nobody thought about, and the "do you actually know it could be re-identified" test is a separate question again. Software that claimed to de-identify data automatically would be the most dangerous thing here: get it wrong and a record leaves with no protection and no way to call it back.
Contracts with your suppliers164.308(b) · 164.314 ✓ A register of business associates with the dates of their agreements — and a disclosure to one of them is checked against whether a current agreement exists. An expired contract stops being paperwork and starts being a refusal.
How much you may charge for a copy164.524(c)(4) ⚙ Built: the fee is itemised into the four components the rule permits and nothing else, and the request warns when the total goes over your cap.

You set: the cap itself. The regulation names no figure — it says "reasonable, cost-based", and the federal guidance and the case law on what that means have moved and will move again. So the cap is a setting on your company rather than a number written into the software that somebody would have to find and edit. Agree it with your counsel and enter it once.
Six years of documentation164.316(b)(2) ✓ Shipped as retention rules, including the one for minors that runs to adulthood plus six years. Every period counts from a stored date — last contact, date of birth, date of death — rather than from when a file happened to be created.
04 — The one that matters most here

Psychotherapy notes, and why access rules alone are not enough

HIPAA treats a therapist's own process notes differently from the clinical record, on the condition that they are separately maintained. In most systems "separately maintained" becomes a permission setting. A permission setting can be changed by whoever administers the system, which means the separation is only as good as the configuration on any given day.

Here it is enforced by the encryption itself. That is a stronger claim, and it is worth understanding exactly how it works, because it is the thing a reviewer should test.

How the separation is enforced

Four mechanisms, not one

  1. A second encryption keyPsychotherapy notes are encrypted under their own key, held at its own path on the server. The key that opens the ordinary clinical record does not decrypt them.
  2. Excluded from the record setThey sit outside the designated record set, so a subject access request cannot produce them even when fulfilled correctly.
  3. A patient grant is refused at every pathIncluding a direct write to the access-rule table. There is no route by which the rule can be created, correct or otherwise.
  4. The label cannot be changed afterwardsA document already filed cannot be moved into the notes key space later, because its content is already encrypted under the ordinary key. The decision is made once, at filing.

What that means in practice

The consequences, including the awkward ones

  1. Configuration is required before go-liveThe second key path must be set in the server configuration. Without it, filing a psychotherapy note fails outright.
  2. It fails rather than falling backIt does not quietly use the main key if the second one is missing. A silent fallback would destroy the separation without anyone noticing.
  3. The second key needs its own custodySame rules as the main key: outside the database, outside the file store, and never in the same backup as either.
  4. Losing that key loses those notesPermanently, and by design. It must be backed up, separately from the data it protects.
  5. The care team still reaches themSeparation is from the patient's access right and from the record set. It is not isolation from the clinician who wrote them.
05 — Security Rule: the technical half

The eight things the software itself has to do

The Security Rule marks each requirement required or addressable. Addressable does not mean optional — it means you either do it, or you write down why an alternative is reasonable. All eight below are built.

SafeguardStatusWhat is built
Everyone has their own login164.312(a)(2)(i) · required ✓ Shared logins are not a supported way to run the system, because the moment two people share an account the audit log stops being able to answer who did anything.
A way in during an emergency164.312(a)(2)(ii) · required ✓ A clinician can reach a record they have no relationship with in a genuine emergency by opening what is called a break-glass session. It is recorded as an event and reviewed afterwards. Access is available when somebody truly needs it, and never silent.
Screens lock themselves164.312(a)(2)(iii) · addressable ✓ Enforced on the server, not in the browser. Every request checks how long it has been since that session was used and refuses it if the answer is too long — so switching the timer off in a browser buys nothing. The browser's job is only to warn first, so nobody loses a half-written note to a control meant to protect them. Three settings per company: idle minutes (fifteen by default), how long the warning shows, and a ceiling regardless of activity. The same check runs for the mobile app.
Records are encrypted164.312(a)(2)(iv) · addressable ✓ Every version of every clinical document gets its own key, and those keys are locked under a master key kept outside the database. There is no setting in which documents are stored unencrypted. This is also what earns the exemption from telling patients after a breach. The secure documents page explains how it works and names the risks that have no technical fix.
Every look is recorded164.312(b) · required ✓ Openings, not only changes. The entry is written before the content is handed over. The log is append-only and each entry is mathematically tied to the one before it, so removing or altering one is detectable. Administrators cannot edit it either.
Records cannot be silently corrupted164.312(c)(1) · required ✓ Each version stores a fingerprint of both its readable content and its encrypted content, and both are checked when the document is opened. Tampering or disk corruption is detected rather than served up as if nothing happened.
People are who they say they are164.312(d) · required ✓ Password sign-in for staff, and short-lived signed tokens for the mobile app issued after a password check. Passwords are stored only as one-way hashes.
Data is protected while it travels164.312(e) · addressable ✓ Encrypted connections everywhere, with unencrypted requests redirected rather than served — and now evidenced rather than assumed. A transmission check records each place health information goes in or out and what protects it, so the control can be shown in an audit instead of asserted in a meeting.
06 — Security Rule: the administrative half

The programme, and why it is in the software at all

Most of the Security Rule is not about technology. It is about what your organisation does: who is responsible, what the risks are, who reviewed what, who was trained, what happens when somebody leaves, and what you do if the building burns down.

None of that is something software performs for you. What software can do is give each of those things a place to live, so that when an investigator asks for them the answer is a record rather than a search through somebody's email. That is what these are.

These are also the two most frequently cited findings in United States enforcement — the risk analysis, and the review of the audit logs. Not "do you have security", but "show me the assessment", and "show me that somebody actually reads the logs".

What the rule asks forStatusWhat is built
A risk analysis, kept current164.308(a)(1)(ii)(A)–(B) ✓ A register: each risk with its asset, threat, weakness, likelihood, impact, the control already in place, the risk left over, an owner and a review date — and the plan for reducing it attached. An assessment cannot be approved while any risk is unrated, and one with no risks in it cannot be approved at all: an empty register is the finding, not a clean bill of health.
Somebody actually reads the audit logs164.308(a)(1)(ii)(D) ✓ The requirement is to review the logs regularly, not merely to keep them. So there is a review record with a period, a named reviewer, what was examined, and a findings trail. An empty findings list is the good outcome — but it has to be an empty list somebody produced, not an absence.
A named security officer and privacy officer164.308(a)(2) · 164.530(a) ✓ Both required by name, along with a contact point for complaints. Held as designations with dates, so "who was the privacy officer in March" has an answer.
Consequences when staff break the rules164.308(a)(1)(ii)(C) · 164.530(e) ✓ A record of the policy, and a record of sanctions actually applied. The second one is what gets asked for.
Who is authorised, and reviewing it164.308(a)(3)–(4) ✓ An authorisation register — who was granted what, by whom, and when it was last reviewed — and a termination record, which is the one that matters: the evidence that access was removed on the day somebody left rather than three months later.
Training, recorded per person164.308(a)(5) · 164.530(b) ✓ Training records per member of staff, alongside the skills and certifications with expiry dates the practice already tracked.
Written policies, versioned and kept164.316 · 164.530(i)–(j) ✓ Policies as versioned documents with acknowledgements, and the six-year retention clock running on each version rather than on the current one.
A plan for when things fail164.308(a)(7) ✓ The contingency plan, its tests with their results, and the analysis of which systems and data matter most. A backup nobody has restored is a hope rather than a control, so the test records are the point.
Re-checking it all periodically164.308(a)(8) ✓ An evaluation record with a cadence, so "when did you last check whether any of this is still true" has a date on it.
The honest limit on all nine of these

Every one of these is a place to put a record. A risk register with nothing in it evidences nothing. A review record nobody creates proves nothing. An investigator will look at the records, not at the fact that the software has somewhere to keep them. That work is yours, and no product changes it — what the product removes is the excuse that there was nowhere to write it down.

07 — Security Rule: the physical half

Two of these four standards are about records, not locks

It is easy to read the physical safeguards as "put a lock on the door" and conclude software has nothing to offer. That is half right. The rule says outright that you must keep a record of the movements of hardware and media, and of who was responsible. What an investigator asks after a stolen laptop is not what lock you used. It is where that laptop went, who had it, and what happened to the disk.

StandardStatusWhat is built
Facility access controls164.310(a) ✓ A register of facilities with who may enter, plus maintenance records — the repairs and changes to the physical parts of a building related to security.
Workstation use and security164.310(b)–(c) ✓ A register of workstations: where each one is, what it may be used for, and what protects it. A reception screen facing a waiting room is a different answer from a locked office.
Device and media controls164.310(d) ✓ Every device, and every movement of it, with the person responsible. A device cannot be marked disposed of or re-used without recording what was done to the data — because a laptop retired with the register saying "disposed" and nothing anywhere saying the disk was wiped is the commonest finding in this part of the rule. A register that cannot answer that question is worse than no register, because it looks like evidence.
08 — The Breach Notification Rule

What happens after information gets out

This rule is the reason the encryption is built the way it is. If the information that escaped was properly encrypted and the keys were not taken, it is treated as unreadable and you do not have to notify the patients. That exemption is called the safe harbour, and everything about how the keys are stored exists to be able to prove it.

What follows is the assessment the rule requires, and all of it is built.

What the rule asks forStatusWhat is built
Assess it against four factors164.402 ✓ What the information was, who received it, whether it was actually looked at, and how far the damage was contained. Answering all four produces the conclusion the rule calls a "low probability of compromise". The default is that patients must be told — the four factors are how you argue otherwise, not a form you fill in to make the problem go away.
Tell the patients within 60 days164.404 ✓ Counted from discovery, worked out by the system rather than typed. The notice itself is generated with all five pieces of content the rule requires.
Tell the media above 500 in one state164.406 ✓ The threshold is per state, not per breach, so a total is not enough to answer it: 600 people spread over three states crosses nothing, and 600 in one state crosses both this and the immediate federal report. The system asks for the state-by-state numbers, and where they are missing and the total is over 500 it says the question is unanswered rather than assuming the comfortable answer.
Tell the federal health department164.408 ✓ At 500 or more, at the same time as the patients. Below 500, on an annual log filed within 60 days of the end of the calendar year. Both are tracked, because the second one is the one people forget in February.
When a supplier is the one who finds it164.410 ✓ Built as two clocks, because that is what it is: the supplier has 60 days from its own discovery, and your 60 days start when they tell you. A breach can therefore be 118 days old with nobody having missed a deadline — and a supplier who took longer is a problem with the contract, not with your breach record.
When law enforcement asks you to wait164.412 ✓ The asymmetry here is the whole rule. A written request delays notification for the period it names. An oral one delays it for thirty days and no longer, unless something written arrives within them. Storing "law enforcement asked us to wait" as a simple yes/no would delay indefinitely on the strength of a phone call, which is exactly what the thirty-day cap exists to prevent. When a delay lapses, the system says so — nothing else would.
The encryption exemption164.402 definition ✓ Two separate stored questions: was the data encrypted, and were the keys taken. An unanswered keys question counts against the exemption. You cannot close a breach as non-notifiable by leaving the awkward field blank, and closing it that way requires writing down the evidence.
Why the access log is the investigation

Because every opening of a record was written down before the content was handed over, the question "what was actually exposed, and to whom?" has a real answer rather than an estimate. That is the difference between notifying eleven people and notifying everybody in your database — and it is usually the difference between a contained incident and a front-page one.

09 — 42 CFR Part 2

Substance-use records, and the notice that travels with them

Part 2 is a separate federal rule and it is stricter than HIPAA. It covers records held by federally assisted substance-use treatment programmes. If your service treats addiction alongside other mental-health work, some of your records fall under it and some do not — which is exactly why the labelling has to live on the record itself rather than in somebody's head.

A 2024 rule change brought Part 2 much closer to HIPAA. All of it is built.

What the rule asks forStatusWhat is built
A notice forbidding onward sharing ✓ Documents labelled restricted carry the notice on every disclosure, and the system generates the wording rather than asking staff to type it. A notice people retype is a notice that eventually says something slightly different.
Part 2 material is labelled at the record ✓ So a disclosure knows what it is handling without anybody having to remember which patient that is.
One consent covering treatment, payment and operations2024 rule ✓ The 2024 change replaced a separate consent per disclosure with a single one covering all three. That structure is modelled, it can be revoked, and the system refuses combinations that do not make sense.
Restrictions that understand Part 22024 rule ✓ A restriction carries its Part 2 scope and knows whether every document it covers is Part 2 material. The Part 2 check runs before the general one — a general check that ran first and permitted the disclosure would never reach the Part 2 question, and would be right only on the days the two happened to agree.
Part 2 breach notification2024 rule ✓ The 2024 rule made Part 2 breaches follow the HIPAA process, which is built. A breach involving Part 2 material runs through the same assessment and the same deadlines.
A patient notice of its own ✓ Versioned the same way as the HIPAA privacy notice, with one active notice per kind. The two do not get confused: publishing a Part 2 notice does not make every patient look as though they owe an acknowledgement on a notice never meant for them.
Part 2's own accounting rules ◐ Built: Part 2 disclosures are flagged as such, carry the redisclosure notice, and have their own view with its own period.

What remains: Part 2's counting rules are not modelled separately from HIPAA's. Where the two regimes would count a disclosure differently, the register answers with the HIPAA rule. In practice the difference is narrow, but if your service is principally a Part 2 programme rather than a mental-health practice that also treats addiction, raise it with us before go-live.
Check the date, and check whether it reaches you at all

The compliance date for the 2024 rule was 16 February 2026, so it is in force. Two questions remain that no software answers: whether Part 2 reaches your particular programme, and whether the wording of the notice is right. Everything Part 2 adds is inert until somebody switches it on, and the wording needs your counsel — the regulation prescribes its content.

10 — How it works day to day

Seven things that happen in a real clinic, step by step

Everything above says what exists. This says what happens — the actual sequence inside the software when somebody asks for their record, when a correction is refused, when information is shared, when something gets out.

Read these if you want to know what your staff will experience, or if you are being asked to sign off on the platform and would like to see the machinery rather than a list of features. Each step is one thing the software or a person does, in the order it happens.

1 the software does this by itself 1 a person decides or writes something ✕ the software refuses, and says why
Flow 1 · 45 CFR 164.524 A patient asks for a copy of their record The most heavily enforced right in United States health privacy. Most penalties in this area are one of four things: too slow, charged too much, sent in a form nobody asked for, or refused without a proper basis. Each of those has a step below.
  1. The request is logged with what they asked for, in their words

    Not summarised into a category. The scope in the patient's own wording is what the response is later measured against.

  2. The deadline appears by itself

    Thirty days from the request, worked out by the system. Nobody types a date, so nobody types the wrong one. The deadline is shown on the request from the moment it exists.

    164.524(b)(2)(i)
  3. Staff gather the documents

    They pick the records that answer the request.

  4. Anything outside the designated record set is refused

    The rule entitles a patient to a defined set, not to everything the clinic holds. If somebody adds a document type that sits outside it, the software refuses and says how many and why. Psychotherapy notes are refused here too, separately and by name.

    164.501 · 164.524
  5. The patient's preferred format is recorded

    Electronic, paper, or something else agreed with them. If the clinic could not produce what was asked for, the software will not let the request close until what was agreed instead is written down — because the rule is about an agreement, and an agreement nobody recorded cannot be shown.

    164.524(c)(2)
  6. If a fee is charged, it is itemised into the four permitted things

    Labour, supplies, postage, and a summary if one was asked for. Not retrieval, not search, not the cost of running the system — those are the extras that appear in most enforcement settlements, and there is nowhere to type them. If the total goes over the cap you configured, the request says so.

    164.524(c)(4)
  7. If they want it sent to somebody else, their written instruction is attached

    The patient can direct a copy to a person or organisation they name. That is their right, not a disclosure the clinic decides on — so the software stores the signed instruction rather than accepting that somebody remembers a phone call.

    164.524(c)(3)(ii)
  8. If more time is genuinely needed, one extension is available

    Up to thirty days, once. It records the reason and, separately, the date the patient was actually told — because an extension nobody was told about is not an extension. The original statutory date stays visible next to the new one, so the record shows how much time the extension actually bought.

    164.524(b)(2)(ii)
  9. The response goes out, and what was held back is written down

    A partial response that does not say what is missing is a response nobody can challenge, so the closing note is required.

  10. Every document sent is written to the access log

    Individually. A bulk export is not a way to hand over a record without leaving a trace of each item in it.

If the request is refused instead: the reason must come from a closed list of grounds the rule allows — a refusal on a ground that is not one of them is a refusal without a basis. The software knows which grounds carry a right of review and which do not, so it will not let staff offer a review that does not exist, nor deny one that does. Where a review applies, it must be done by a named professional who was not part of the original decision, and that is enforced rather than left to procedure.
Flow 2 · 45 CFR 164.526 A patient asks for a correction, and the clinic disagrees Accepting a correction is easy. What most systems get wrong is what happens when the clinic says no — and the rule has quite a lot to say about that.
  1. The request records what they want changed and why

    Against a specific document, not against "their file".

  2. A sixty-day deadline appears, with one extension available

    The same extension machinery as the access request, written once and used by both, so the two cannot drift apart.

    164.526(b)(2)
  3. The clinic accepts or refuses, and says who decided

    If accepted, the correction is filed as a new version. The original is never overwritten — a record that can be quietly edited is worth nothing as evidence.

  4. On acceptance, people who already have the old version can be told

    An amendment nobody downstream hears about is an amendment that does not reach the place it was needed.

    164.526(c)(3)
  5. On refusal, the patient may file a statement of disagreement

    Their words, kept as their words.

    164.526(d)(1)(iii)
  6. The clinic may write a reply to it

    Optional, and recorded with its date.

    164.526(d)(4)
  7. From then on, both travel with the record automatically

    This is the step that matters and the one most often missed. Once a disagreement exists, any future sharing of that document automatically carries the request, the refusal, the patient's statement and the clinic's reply. Nobody has to remember. The packet is attached at the moment the disclosure is recorded, and it cannot be edited afterwards — it is a record of what the recipient was actually sent.

    164.526(d)(5)
Why this one is worth the trouble: a patient who disagreed with their record and was overruled is exactly the patient who later complains. The version history shows the original untouched, the refusal shows who decided and why, and every subsequent disclosure carries their objection alongside it. That is a defensible position rather than an argument about what was intended.
Flow 3 · 164.502 · 164.508 · 164.510 · 164.528 · 42 CFR Part 2 A record is shared with somebody outside the clinic A referral, a court order, an insurer, a family member. This is the flow with the most checks in it, because it is the one where several rules meet at the same moment — and they have to be checked in the right order.
  1. Staff record who it went to, what went, and on what basis

    The basis is the legal reason: treatment, payment, a signed authorisation, a legal requirement, the patient's own request. It is a choice from a list, not free text, because the question afterwards is always which one it was.

  2. If it relies on an authorisation, the authorisation must be named

    Not "we had consent". A link to the signed document. Without it the entry is refused.

    164.508
  3. If it goes to a supplier, their contract must be current

    The business associate register is checked. An expired agreement stops being paperwork and becomes a refusal.

    164.308(b) · 164.314
  4. If the patient objected to this person being told, it is blocked

    Under the rule a patient can object to a named family member or friend being told anything about their care, and that objection is binding. The software refuses the entry and names who objected and when. It does not block where the disclosure rests on a signed authorisation, a legal requirement, or the patient's own request — those are not covered by this rule and the objection does not reach them.

    164.510(b)
  5. Part 2 material is checked before the general check, not after

    The order is not a nicety. A general check that ran first and permitted the disclosure would never reach the Part 2 question, and would be right only on the days the two happened to agree.

    42 CFR 2.26
  6. If it is Part 2 material, the notice is attached automatically

    Generated, not typed, so the wording cannot drift between one member of staff and the next.

  7. If there is an unresolved correction dispute, that packet is attached too

    Automatically, as Flow 2 describes — unless the disclosure is to the patient themselves, in which case handing them back their own statement would be noise rather than a safeguard.

    164.526(d)(5)
  8. The register entry and the access-log entry are written together

    Deliberately in the same moment. A disclosure that appears in one and not the other is precisely the discrepancy an investigation looks for.

  9. Afterwards, what was shared, about whom and when cannot be edited

    Corrections are allowed as new entries. Rewriting history is not, and entries cannot be deleted at all — a patient may ask for six years of them, and a register that can be emptied answers nothing.

    164.528
When the patient asks who has seen their information, the answer is gathered from every register in the system rather than one of them. That sounds obvious and was not: there were two registers in use and neither could see the other, so an accounting could have handed somebody six disclosures out of eight with nothing on the page to suggest anything was missing.
Flow 4 · 45 CFR 164.400–412 Information gets out A stolen laptop, an email to the wrong address, a misconfigured server. This is the flow everybody hopes never to run, and the one an investigator will read line by line.
  1. The moment you became aware is recorded first

    Not the moment it happened. Every deadline runs from awareness, so establishing that moment is the first step rather than something reconstructed under pressure three weeks later.

  2. What was involved, and who, is attached from the records

    The documents and the people, taken from the system rather than estimated — which is what the access log makes possible.

  3. Two questions about encryption are asked separately

    Was the data encrypted, and were the keys taken. They are separate because the answer to the first means nothing without the second.

  4. An unanswered keys question counts against you

    You cannot close a breach as not notifiable by leaving the awkward field blank, and closing it that way requires writing down the evidence — where the key was, who could reach it, and why the incident did not touch it.

    164.402
  5. The four factors are answered, in writing

    What the information was, who received it, whether it was actually looked at, and how far the damage was contained. The default is that patients must be told; these four are how a clinic argues otherwise, and the argument has to be written down and attributed.

    164.402
  6. The deadlines and thresholds are worked out

    Sixty days to tell the patients. Media notice if more than 500 residents of any one state are affected — counted per state, so the system asks for the state-by-state numbers. The federal department told immediately at 500 or more, or on the annual log below that.

    164.404 · 164.406 · 164.408
  7. If a supplier found it, both clocks run

    Theirs from their own discovery, yours from being told. A breach can be 118 days old with nobody having missed a deadline.

    164.410
  8. If law enforcement asks you to wait, the form of the request matters

    Written delays you for the period it names. Oral delays you for thirty days and no longer unless something written arrives inside them — and when the delay lapses the system says so, because nothing else would.

    164.412
  9. The notices are generated with the content the rule prescribes

    All five required elements, in a draft with every element present. The wording still needs your counsel; what is removed is the blank page and the missed element.

  10. Everything above stays as the record of the decision

    The dates, the factors, the reasoning, who determined what and when. That is the document you hand to a regulator, and it exists because it was built as you went rather than assembled afterwards.

Flow 5 · 45 CFR 164.520 A new patient arrives and is given the privacy notice Small, routine, and one of the easiest findings for an investigator to collect — because the rule asks for evidence of something that usually happens at a busy reception desk.
  1. The notice exists as a versioned document with an effective date

    Not a PDF on a shared drive. One active notice per kind, per company.

  2. A notice cannot be published while any required element is unfilled

    It ships as a draft where every element the rule lists has its own named slot carrying its citation. Publishing is refused while any slot is still marked to be completed, and the refusal names which ones — so a template cannot go live verbatim because somebody filled in three sections and got called away.

  3. The patient is given the notice and asked to acknowledge it
  4. The acknowledgement is recorded — including when it fails

    This is the part most systems miss. The rule asks for a good-faith effort to obtain a written acknowledgement and documentation of a failure to get one. So "declined" and "not obtainable" are recorded outcomes with a reason, not an empty field.

    164.520(c)(2)(ii)
  5. It can be a real signature rather than a tick

    Through the e-signature module, which runs on your own servers — no document leaves the estate to be signed.

  6. A material change makes a new version, not an edit

    The old version is superseded and kept. Who acknowledged which version, and when, stays answerable for as long as it needs to be.

    164.520(c)(1)(i)(C)
  7. A work list shows who still owes an acknowledgement

    So it is a queue somebody works rather than a discovery made during an audit.

Flow 6 · 164.312(a)(2)(iii) · 164.312(a)(2)(ii) · 164.312(b) A clinician opens a record, and then walks away from the screen The most ordinary flow on this page, and the one an investigator checks in the first ten minutes. It is also where three separate safeguards meet.
  1. The clinician opens a client's record

    They reach it because they hold a current care relationship with that person — not because of their job title. A therapist reaches their own caseload, not the clinic's.

  2. The opening is written to the log before the content appears

    Before, not after. If the write fails, the content is not served. The log is append-only and each entry is tied to the one before it, so an entry cannot be removed without leaving a break.

    164.312(b)
  3. If they had no relationship with that person, nothing opens

    Not a warning. There is no master override, and an administrator account opens no clinical content by itself.

  4. If it is a genuine emergency, they can break glass instead

    A deliberate, separate act that opens a recorded session. Access is available when somebody truly needs it, and never silent.

    164.312(a)(2)(ii)
  5. They are called away, and the screen goes idle
  6. A warning appears before anything is lost

    Long enough to come back and carry on. Nobody should lose a half-written clinical note to a control that exists to protect them.

  7. The session ends — and the server is what ends it

    This is the part that matters. The timer in the browser is a courtesy; the server checks how long it has been since that session was last used and refuses the request. Turning the browser timer off buys nothing, and a session token replayed from somewhere else is refused on the same rule.

    164.312(a)(2)(iii)
  8. A ceiling applies regardless of activity

    Because a session kept alive by a script is still a session that should end. Idle minutes, warning period and absolute ceiling are three settings on the company — fifteen minutes idle by default, which is where most United States practices land.

  9. The mobile app follows the same rule

    Checked in the gateway, held in shared state so the answer is the same across every server process, and the app does not quietly refresh its way past a session the server already ended.

Break-glass is not the end of that story. Every emergency access produces a record that is reviewed afterwards by the privacy officer. The control is the review, not the recording — which is why it appears again in the next flow.
Flow 7 · 164.308(a)(1)(ii)(A)–(D) · (a)(2)–(8) · 164.530 The compliance year, from one end to the other Not an incident — the routine. This is the flow that turns a system with good controls into an organisation that can prove it had them, and it is where the two most-cited findings in United States enforcement live.
  1. A security officer and a privacy officer are named

    By name, with dates, along with a contact point for complaints. An unfilled designation is a finding on its own.

    164.308(a)(2) · 164.530(a)
  2. The risk analysis is carried out and written into the register

    Each risk with its asset, threat, weakness, likelihood, impact, existing control, the risk left over, an owner and a review date. This is the single most frequently cited finding in United States enforcement — not the absence of security, the absence of the assessment.

    164.308(a)(1)(ii)(A)
  3. An assessment with unrated risks cannot be approved

    And an assessment with no risks in it cannot be approved at all. An empty register is the finding, not a clean bill of health.

  4. Anything to be mitigated carries an owner and a date

    Which is what makes the register a plan rather than a list of worries.

    164.308(a)(1)(ii)(B)
  5. Somebody reviews the audit logs on a stated cadence

    The requirement is to review them regularly, not merely to keep them. The review records the period, the reviewer, what was examined and what was found — including the break-glass sessions from Flow 6. An empty findings list is the good outcome, but it has to be an empty list somebody produced.

    164.308(a)(1)(ii)(D)
  6. Joiners are authorised; leavers are terminated on the record

    The authorisation register says who was granted what and when it was last reviewed. The termination record is the one that gets asked for: the evidence that access was removed on the day somebody left, rather than three months later when somebody noticed.

    164.308(a)(3)–(4)
  7. Training is recorded per person

    Alongside the skills and certifications with expiry dates the practice already tracks, so one screen answers "is this person current".

    164.308(a)(5) · 164.530(b)
  8. Policies are versioned, acknowledged, and kept for six years per version

    The clock runs on each version rather than on the current one, which is what the rule actually says and what most filing systems get wrong.

    164.316 · 164.530(i)–(j)
  9. The contingency plan is tested, and the test is recorded

    Backup, recovery, emergency operation, and which systems matter most. A backup nobody has ever restored is a hope rather than a control.

    164.308(a)(7)
  10. Devices and workstations are on the register, and movements are logged

    And a device cannot be marked disposed of or re-used without recording what was done to the data on it.

    164.310(b)–(d)
  11. Where somebody breaks the rules, the sanction is recorded

    The policy, and the sanctions actually applied. The second one is what gets asked for.

    164.308(a)(1)(ii)(C) · 164.530(e)
  12. Once a year, the whole thing is re-evaluated and dated

    So that "when did you last check whether any of this is still true" has an answer with a date on it.

    164.308(a)(8)
  13. Retention runs quietly in the background all year

    When a period expires, the encryption key is destroyed. The content becomes permanently unreadable while the empty shell and the audit trail remain, so you can prove the record existed and was disposed of on schedule. Nothing is destroyed while a legal hold stands.

    164.310(d)(2)(i) · 164.316(b)(2)
The one warning worth repeating: every step above is a place to put a record, and a place with nothing in it evidences nothing. The software removes the excuse that there was nowhere to write it down. It does not do the year for you — and it will not tell you that you skipped it, except by having an empty register when somebody asks.
11 — Where the edges are

What is not finished, said out loud

This section exists because the alternative is worse. A gap you name is one a buyer can plan around. A gap they find during due diligence, after being told the position was complete, costs the deal and the trust with it.

The list used to be long. Breach notification, the privacy notice, automatic logoff, the missing parts of the access right, confidential communications, risk analysis, log review, sanctions, named officials, training, termination, contingency planning, physical safeguards, de-identification and the rest of Part 164 have all been built. What remains is genuinely small, and it is the honest remainder rather than a tidied one.

Still open in the software

  • Refused attempts are missing from the log. Successful openings are recorded properly. An attempt that was blocked is written and then lost, because the refusal ends the request and the system discards the request's work along with it. So the log answers "who read this record" and cannot yet answer "who tried and was turned away" — which is one of the things a periodic log review is for. Found while building the two-step verification control, and being fixed separately.
  • There is no record of who may act for a patient. We can record that a parent or a court-appointed guardian signed a form. We cannot yet record that a named person may read a patient's record — so a parent's authority cannot be given an end date, and it cannot be switched off. Two things follow, and they matter most in adolescent work. There is no place to record which of the three situations applies where a parent is not the representative of their teenage child. And there is no way to refuse someone as a representative where the practice believes that person may have harmed the patient — a decision the law expressly allows, and one that today depends on everybody remembering. Until this ships, do not treat the system as the record of who may act for whom; that stays on paper.
  • "Minimum necessary" is enforced by structure, not decided automatically. Staff reach their own caseload rather than the clinic's, which is the part that matters. On the sharing path the exempt purposes and the judgement made are recorded rather than computed. Expect to show a policy and a record here, not an algorithm — and be suspicious of any product that claims otherwise.
  • Part 2's own accounting rules are not separately modelled. The register flags Part 2 material and carries the notice, but the two regimes' counting rules are handled as one.
  • There is no supplier-facing surface for breach notification. Your side of it is built properly, with both clocks. What does not exist is a way for a business associate to file a notification themselves — that would be a portal for outside organisations, which is a product decision rather than a missing check.
  • The e-signature bridge for notice acknowledgements has no tests of its own. It is small and the models on both sides are well covered, which makes it low risk rather than tested.
  • Encrypted documents cannot be searched by their content. This follows directly from the encryption and will not change. Documents are found by patient, type and date. Any supplier promising both strong encryption and full-text search of the same content is promising one of them falsely.
  • It is not an electronic health record. No clinical charting, no structured notes, no HL7 or FHIR messaging, no e-prescribing. If you need those they come from another system, and this one holds the documents.

Built, but only as good as the use you make of it

These are all implemented, and they are the kind of control that fails silently if nobody runs it. An investigator looks at the records, not at whether the software has somewhere to keep them.

  • The risk analysis has to actually be done. The register is empty until somebody fills it in, and it is the most cited finding in the country.
  • The log review has to happen on its cadence. Keeping logs is not reviewing them.
  • The contingency plan has to be tested. The test record is the evidence, not the plan.
  • The officials have to be appointed by name. An unfilled designation is a finding.
  • Break-glass sessions have to be read. The system records every one. Somebody has to look at them and act on what they show.
  • The scheduled jobs have to keep running. Retention, disposal, session expiry, deadline warnings. A job that stops quietly is a compliance problem that only surfaces in an audit.
12 — Your side of the line

What HIPAA asks of your organisation, not of any software

A large part of these rules is about how an organisation behaves. No product does these for you, and a product claiming to is misrepresenting the rule.

This is not legal advice, and no product is HIPAA certified

There is no HIPAA certification for software, because no authority issues one. What exists is a set of controls, and this page says which of them the platform implements. Everything below stays with you, and every item on this page should be confirmed with United States healthcare counsel before it reaches a contract.

  • The agreements are yours to sign. The platform registers business associate agreements, tracks their dates and refuses a disclosure resting on an expired one. It does not execute them.
  • The prescribed wording needs a lawyer. The privacy notice, the Part 2 notice and the breach notices ship as drafts where every required element has its own slot carrying its citation, and none can be published with a slot unfilled. The regulation prescribes their content. Reviewing the words is counsel's, and no amount of code closes it. This is the one item on this page that stands between the current state and a United States go-live.
  • Administrative decisions stay decisions. Who is cleared, what training says, whether a sanction is warranted, how you respond to an incident. The system records the evidence; the judgements are yours.
  • Physical security is about your building. The registers hold the evidence — who may enter, where each workstation is, where each device went. The locks, the cameras and the visitor policy are yours.
  • State law goes further than HIPAA. California's CMIA, and rules in New York and Texas among others, add requirements HIPAA does not. Retention periods in particular vary and must be confirmed locally.
  • Who gets a care relationship in the first place. The system enforces access through care relationships. It does not decide who should have one.
  • Whether Part 2 reaches you at all. Everything Part 2 adds is inert until somebody switches it on, and whether it applies to your programme is a question for counsel.
The honest summary, in one paragraph

All eight technical safeguards are built and demonstrable. The Privacy Rule is complete through the parts most systems leave out — the designated record set, psychotherapy notes separated by a second encryption key, the self-pay restriction the software will not let staff refuse, six years of disclosures gathered from every register, the access right with its extension, fees, format, third-party transmission and denial review, and the correction right through disagreement and reply. The Breach Notification Rule is built with the four factors, the sixty-day clock, the per-state media threshold, both supplier clocks and the thirty-day cap on an oral law-enforcement request. 42 CFR Part 2 is covered including the 2024 rule. The administrative and physical safeguards have records to live in — and those records are worth exactly what you put in them, which is the real remaining risk and an organisational one rather than a software one. All of it is covered by 521 automated tests that run against a live installation.