Trust & security

How we handle your data, your records, and your trust.

NeuroPath Health is in early pilot phase. We’re building our formal trust documentation in partnership with our first institutional customers — and we’re happy to share what we have today with any partner in procurement review.

HIPAA

HIPAA Posture

NeuroPath Health operates under a HIPAA-aligned architecture. Our school deployments do not require Protected Health Information (PHI) — district-facing workflows use educational records governed by FERPA, which keeps the system outside HIPAA’s scope for those customers. Hospital and clinical deployments that handle PHI operate under a signed Business Associate Agreement (BAA).

  • PHI is stored and transmitted only where clinically required; never in school-side workflows.
  • Minimum-necessary data principle applied at every integration boundary.
  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls and audit logging for all PHI interactions.
  • BAA template available on request for pilot partners handling PHI.

Note for institutional buyers: Our HIPAA documentation — BAA template, risk assessment, and administrative/technical/physical safeguards summary — is available on request. We’re actively building toward a full HIPAA compliance attestation and will publish it here when complete.

Security

Security Program

NeuroPath Health is built on Google Cloud infrastructure with modern security controls from the ground up. Our program emphasizes defense in depth, least-privilege access, and continuous monitoring.

  • Infrastructure: Google Cloud Platform, with Vertex AI VPC for model operations.
  • Encryption: TLS 1.2+ in transit, AES-256 at rest.
  • Authentication: Staff SSO with multi-factor authentication; Firebase Auth with MFA for admin users.
  • Access control: Role-based permissions, principle of least privilege, separation of duties.
  • Audit logging: All PHI/PII access logged with immutable audit trail.
  • Code review and secrets management: Git-based review, secrets stored in managed secret stores (never in source).
  • Dependency monitoring: Automated vulnerability scanning on all third-party packages.
  • Independent assessments: SOC 2 Type I is under active planning. Our target is to complete Type I in our first full operating year and progress to Type II thereafter. Penetration testing cadence and scope will be published alongside the Type I attestation. Pilot partners with accelerated procurement timelines can request a tailored security review.
Security questions or responsible disclosure: security@neuropathhealth.com
EHR Connections

How medical-record connections work

NeuroPath does not integrate into a hospital’s EHR and never queries it directly. A record reaches NeuroPath only when a family chooses to connect their own child’s record, using the patient-directed access every patient is entitled to under the 21st Century Cures Act. There is no interface build, no VPN, and no data project on the hospital’s side.

  • Family-initiated, per-connection consent. A caregiver connects the child’s record by signing in at their own hospital’s patient portal and consenting on the hospital’s authorization screen. NeuroPath never sees portal credentials.
  • Read-only, scoped, revocable. Each connection returns a scoped, time-limited, read-only token for that one patient. No write access. Families can disconnect at any time.
  • Standards-based. Connections use certified SMART on FHIR (R4) patient-access APIs — live with Epic, and in pilot with Oracle Health (Cerner). NeuroPath authenticates as a confidential client with asymmetric keys (a published JWKS) — there is no shared secret to leak.
  • Least privilege. We request read access to a fixed set of USCDI data classes (diagnoses, medications, allergies, labs, vitals, clinical notes, demographics) and nothing more.
  • Bedside use. When a care team uses NeuroPath at the bedside, it works from the family’s connected, consented record shared with the team — not a hospital-system integration.

For hospital security teams: because access is patient-directed and read-only, NeuroPath sits on the patient’s side of the boundary — there is nothing to install in your environment and no connection to your EHR to review. Our public JWKS, requested scopes, and redirect URIs are available on request.

Security questions: security@neuropathhealth.com
Clinical Reliability

Clinical Reliability & Oversight

NeuroPath Health generates clinical-support outputs — student profiles, proposed target behaviors, and candidate intervention plans. Because those outputs inform decisions about real children, human clinical oversight is built into the workflow. This section describes the oversight that is in place today.

Human review of formal plans

Formal outputs — functional behavior assessments (FBAs) and behavior intervention plans (BIPs) — are reviewed by a board-certified behavior analyst before they are used. They are drafts for a clinician to review, refine, and sign — not auto-published documents.

Sampling for clinical review

A sample of generated guidance is routed to a doctoral-level, board-certified reviewer and scored against clinical standards. Scoring is function-based — it emphasizes whether the hypothesized behavioral function is correct, rather than exact wording.

Safety net, always on

Questions involving self-harm, abuse, weapons, or immediate danger trigger a clinician-grade protocol response and crisis resources regardless of plan or usage limits. These safety triggers are hard-coded and not bypassable.

Clinician gating

The engine is designed to decline, hold, or refer out when intervention is not clinically justified — restraint is a feature, not a gap.

Audit trail

Key account and clinical actions are recorded to an audit log with actor identity and timestamp.

Expanded reliability tooling — higher-volume sampling and inter-rater agreement dashboards — is in development and shared with pilot partners as it comes online.

Clinical reliability questions: clinical@neuropathhealth.com
Privacy

Privacy Policy

We’re building NeuroPath Health for families and institutions that have every reason to be careful with data — children with disabilities, their medical records, and the adults who advocate for them. We take that seriously.

What we collect. Depending on the deployment, NeuroPath Health may collect: staff and family account information (name, email, role), product usage telemetry, behavioral observation logs entered by authorized staff, and — in hospital and family deployments — clinical information imported with explicit consent (e.g., MyChart connections made by a parent for their own child).

What we don’t collect. In school deployments, we do not require or ingest Protected Health Information. Student records used for behavioral support are scoped to educational data governed by FERPA.

How we use data. We use data solely to deliver the product to the customer who provided it, to improve the product, and — where permitted and de-identified — to support research that advances the science of behavioral support. We never sell personal data. We don’t use family or student data to train third-party large language models.

Your rights. You can request access to, correction of, or deletion of your data at any time. For school and hospital deployments, the institution (district / hospital) is the data controller; we act as a processor under a Data Processing Agreement (DPA).

Data residency. United States.

Formal policy document. A full Privacy Policy and DPA template are being finalized in partnership with counsel. For the current draft or a deployment-specific DPA, contact us directly.

Privacy questions, data requests, or DPA: privacy@neuropathhealth.com
Terms

Terms of Service

NeuroPath Health is provided as a software-as-a-service tool for authorized institutional customers (schools, hospitals, clinics, care agencies) and, in limited preview, for families of children with behavioral support needs.

Customer data ownership. Your data is yours. Institutions retain ownership of their records; families retain ownership of their child’s records. NeuroPath Health acts as a processor and holds no residual rights to customer data beyond what is necessary to deliver the service.

Acceptable use. NeuroPath Health is a clinical decision support tool, not a replacement for professional clinical judgment, emergency services, or mandated reporting. The product is designed with hard-coded safety triggers that escalate to human authorities in crisis scenarios; those safeguards are not bypassable.

Service availability. We do not currently publish a formal SLA. Pilot agreements include service-availability expectations appropriate to the deployment. A published SLA will accompany our general-availability launch.

Pilot agreements. Pilot deployments are governed by a written agreement that covers scope, data handling, access, term, termination, and any customer-specific compliance requirements. We do not rely on clickthrough terms for institutional customers.

Formal Terms of Service. A complete Terms of Service and Master Services Agreement are being finalized. For the current draft or a pilot-stage agreement, contact us directly.

Legal / contracts: legal@neuropathhealth.com
Billing

Refunds & Cancellations

Cancellations take effect at the end of your current billing period. When you cancel a Family Monthly or Family Annual subscription, you keep full access through your current paid period; at that boundary your account moves to the free tier. Nothing is deleted — journal entries, uploaded documents, share-cards, and Blueprint history all remain accessible. You can re-subscribe at any time.

Refunds. If NeuroPath isn’t the right fit, we offer:

  • Monthly: a full refund within 14 days of any individual monthly charge.
  • Annual: a prorated refund within 60 days of an annual charge.

Email support@neuropathhealth.com — we process within two business days, no forms or questions. Beyond those windows we cannot refund as a default, but we read every message; if your situation has changed materially, let us know and we’ll do what we can.

Hardship. Cost should never be the reason a child can’t access their plan. If paying isn’t workable for your family, email us and we’ll review every case individually.

Disputes & chargebacks. Please contact us before initiating a chargeback — almost every billing question can be resolved by a one-line email faster than a chargeback can be filed, and chargebacks complicate refunds for other customers.

Billing / refunds: support@neuropathhealth.com
Intellectual Property

Patent Pending

NeuroPath Health filed U.S. Provisional Patent Application No. 64/051,551 with the United States Patent and Trademark Office on April 28, 2026, covering core methods underlying the platform’s behavioral intelligence pipeline. The non-provisional application is in preparation.

Use of the “Patent Pending” marking on our marketing materials reflects this active filing and is intended to comply with 35 U.S.C. § 287(a).

IP / patent inquiries: legal@neuropathhealth.com
Pilot-stage disclosure

NeuroPath Health is in early pilot phase. The documentation above reflects our current posture and commitments. Several formal artifacts — full Privacy Policy, Terms of Service, SOC 2 attestation, published SLA — are in active development. We publish this page transparently because we’d rather under-claim today and over-deliver at launch. For any institutional buyer, procurement review, or family with a specific concern, we’re available by email and happy to walk through our current program in detail.