Security & compliance

Built for the data you're trusted with.

Grow Theory is HIPAA compliant. Patient data is encrypted in transit and at rest, access is role-based and audited, and we execute a Business Associate Agreement with every practice we work with.

How your data is protected

Safeguards built in,
not bolted on.

Encrypted in transit and at rest

Patient data is encrypted both on the wire and in storage. Message content, internal notes and any credentials you connect are encrypted again on top of that, before they are ever written down.

Role-based access control

Granular permissions rather than blanket admin rights. A front-desk coordinator, an injector and a practice owner each see what their role requires — scoped to the clinic locations they actually work at.

Audit trail

Sensitive actions are recorded — record access, consent changes, permission changes, exports and charges — so you can always establish who did what, and when.

Isolated per practice

Every request is scoped to your practice in application code, and the database enforces the same boundary independently. Your records are separated from every other practice on the platform.

Patient data stays out of admin tooling

The console we use for account and seat administration has no access to patient records at all — not filtered out, simply never reachable from it.

Independently penetration tested

An independent security firm tested the running platform in 2026, and we re-verified the result against the deployed system afterwards.

Business Associate Agreement

Signed as part
of onboarding

Grow Theory acts as a business associate to your practice. We execute a BAA with every practice we work with, covering how protected health information is used, safeguarded and reported on.

Your compliance officer will want more than a web page. Tell us who they are and we'll send the security overview and the BAA to review before you commit to anything.

Working with patient data

Designed to
minimize exposure

  • Patient details are stripped from application logs and diagnostics
  • Exporting patient data is a separate permission, and asks for confirmation
  • Staff without patient access never see contact details, even on shared records
  • ADA operates through the signed-in user's own permissions — it can never reach data that person couldn't
  • Payment records carry no patient data in their metadata
  • Managers delegate roles beneath their own, never above

Talk to us about compliance.

We'll walk your team through exactly how patient data is handled, and get the paperwork moving early.