Built for therapy data, not ad data.

Miwa is designed for clinicians who handle sensitive mental health information. The platform pairs documentation support with practical safeguards, so care teams can move faster without treating client data casually.

Last reviewed July 2026. Security details are available for practice review.

HIPAA compliant for covered clinical workflows

ePHI is encrypted in transit and at rest, access is role-based and audit-logged, and PHI is only ever processed by vendors under a signed BAA.

Built for HIPAA

Safeguards and BAAs for covered clinical workflows.

BAA available

Business Associate Agreement available for eligible organizations.

No shared-model training

Clinical data is not used to train OpenAI or shared AI models.

Encrypted

Data is protected in transit and at rest.

Access controls

Clinical records are limited to authorized users.

Review ready

Security details are available during practice review.

Privacy commitments that clinicians can explain to clients.

Clinical data does not train shared models

Miwa does not use client notes, transcripts, assessments, treatment plans, or protected health information to train, fine-tune, or improve OpenAI or shared generative AI models.

Sensitive data stays in clinical workflows

Miwa is designed to keep client information inside the product areas that need it, with safeguards around storage, AI assistance, documentation, and support.

Minimum necessary data is the default

Miwa is built to use the least amount of clinical context needed for a task and avoid placing sensitive information where it does not belong.

Clinicians stay in control

Miwa drafts, organizes, and summarizes. Clinicians review and approve. The platform supports documentation, but it does not replace professional judgment, consent obligations, supervision, or clinical recordkeeping.

Practical safeguards for sensitive clinical work.

Miwa protects client information with layered controls across access, storage, AI assistance, support, and operational review. Practices can request additional security detail during onboarding.

Encryption in transit and at rest

Role-based access controls

Clinical data access limits

Operational logging

Vendor review before clinical use

Incident response process

Data minimization practices

Account-scoped AI personalization

What we haven't done yet

We are not yet SOC 2 or HITRUST certified.

We'd rather tell you that plainly than imply a certification we don't hold. We'll update this page as independent reviews are completed.

Miwa is a clinical support tool, not a crisis service. Every AI output is a draft the clinician reviews before it's used. Records are stored securely; clinical data does not train OpenAI or shared generative AI models.

Direct answers to the questions that matter.

Everything else, we're an email away.

Is Miwa HIPAA compliant?+

Miwa is a HIPAA-covered behavioral-health EHR built for HIPAA: ePHI is encrypted in transit and at rest, access is scoped per clinician with audit logging, and PHI is only processed by vendors under a signed BAA. Miwa is not "HIPAA certified" (no such government certification exists); compliance is shared between Miwa and each clinician.

Do you sign a BAA?+

Yes. Miwa can make a Business Associate Agreement available to covered entities and practices using Miwa for covered clinical workflows.

Does AI train on Miwa data?+

Miwa does not use clinical data or protected health information to train, fine-tune, or improve OpenAI or shared generative AI models. Miwa retains authorized records and saved clinician corrections inside the protected account so it can provide memory and account-specific personalization at runtime through approved Zero Data Retention processing.

Is Miwa's AI a licensed professional?+

No. Miwa's AI is a tool. It is not a licensed health professional, does not provide medical, psychological, or clinical advice, and does not imply that any AI output is the advice, care, report, or service of a licensed professional. Every AI-generated draft is reviewed by the clinician before it enters the chart.

Can Miwa staff access PHI?+

Access is limited to authorized operational needs, such as security, support, or troubleshooting.

Do you sell data?+

No. Miwa does not sell client data, therapist data, session data, transcripts, notes, assessment results, or de-identified clinical datasets.

Do you have SOC 2 or HITRUST?+

Not yet. Miwa does not claim SOC 2 or HITRUST certification. We will update this page as additional independent reviews are completed.

Need a BAA or security review?

Send your compliance questions before using Miwa in a covered clinical workflow. We'll help confirm the right contract and privacy configuration.