HIPAA & BUSINESS ASSOCIATE AGREEMENTS
Last updated July 12, 2026
PCIT Tracker is operated by Cubic Insights LLC("Company," "we," "us," or "our"), located at 216 N 2nd St, Fernandina Beach, FL 32034, USA. We operate the website https://www.pcit-tracker.com and related products and services (collectively, the "Services"). This page explains our role under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"), how to put a Business Associate Agreement ("BAA") in place with us, and how to minimize the protected health information ("PHI") you enter into the Services.
OUR ROLE
PCIT Tracker is a professional tool used by clinicians and organizations to track Parent-Child Interaction Therapy sessions, coding, and progress. When a customer that is a HIPAA covered entity (or a business associate of a covered entity) uses the Services to store or process PHI, Cubic Insights LLC acts as a business associate of that customer. In that role, we process PHI only on the customer's behalf and only as permitted by the BAA between us and that customer.
We offer and will sign BAAs with our customers. If you are subject to HIPAA, you must not submit PHI to the Services unless a BAA is in effect between your organization and Cubic Insights LLC.
GETTING A BAA
To request a BAA, email us at admin@pcit-tracker.com from your account or organization contact email. We will provide our standard BAA for signature and can discuss terms with your organization's compliance or legal team as needed.
The BAA must be fully executed before your organization submits any PHI to the Services. Once executed, the BAA (together with any master services agreement or other signed agreement between us) controls over our public Terms of Service and Privacy Policy to the extent of any conflict concerning PHI.
WHAT OUR BAA COVERS
Our standard BAA addresses the obligations HIPAA requires of business associates, including:
- Permitted uses and disclosures. We use and disclose PHI only to provide, support, and secure the Services for the customer, as required by law, or as otherwise expressly permitted by the BAA.
- Safeguards. We maintain administrative, physical, and technical safeguards designed to align with the HIPAA Security Rule, including encryption in transit and at rest, access controls, and audit logging. Our infrastructure runs on Amazon Web Services under a Business Associate Agreement with AWS, so PHI remains within BAA-covered systems end to end. See our Security Overview for details.
- Breach notification. We report breaches of unsecured PHI to the affected customer as required by 45 CFR 164.410, without unreasonable delay and within the timeframes the BAA specifies.
- Subcontractors. Any subcontractor that creates, receives, maintains, or transmits PHI on our behalf is bound by a written agreement imposing protections at least equivalent to those in our BAA. Our current service providers are listed on our Subprocessors page.
- Individual rights support. We support customers in fulfilling individuals' rights of access, amendment, and accounting of disclosures with respect to PHI held in the Services.
- Return or destruction. At termination of the BAA, we return or destroy PHI as the BAA provides, subject to any retention required by law and the purge of residual backup copies on our standard rotation.
MINIMIZE WHAT YOU ENTER
PCIT Tracker is designed around coded identifiers rather than direct identifiers: client and caregiver records use labels, types, and numbers instead of dedicated fields for full names, dates of birth, or contact details. PCIT tracking works well with this approach, and we recommend taking advantage of it:
- Use initials or internal client codes instead of full names in labels.
- Avoid entering dates of birth, addresses, phone numbers, or other contact details in free-text fields where clinically feasible.
- Keep your organization's own key linking codes to identities in your system of record, outside the Services.
Data that has been properly de-identified under the HIPAA de-identification standard (45 CFR 164.514) is not PHI. Minimizing identifiable information reduces risk for your clients and your organization regardless of whether a BAA is in place. That said, the Services will handle identifiable information you do enter in accordance with our Privacy Policy and, where applicable, your BAA.
SECURITY
For an overview of our security practices — encryption, authentication (including two-factor authentication), access controls, audit logging, backups, and incident response — see our Security Overview.
NOT LEGAL ADVICE
This page is provided for general informational purposes and is not legal advice. HIPAA has no official government certification program, and nothing on this page is a representation that your use of the Services will satisfy your legal obligations. You and your organization are responsible for your own determinations about whether HIPAA applies to you, whether the Services are appropriate for your intended use, and how to comply with HIPAA and other applicable laws. Consult your own counsel or compliance professionals.
HOW CAN YOU CONTACT US?
If you have questions about HIPAA, BAAs, or this page, you may contact us by:
- Email: admin@pcit-tracker.com
- Phone: +1 (404) 825-2866
- Mail: 216 N 2nd St, Fernandina Beach, FL 32034, USA