Built for therapy data, not ad data.

Miwa is designed for clinicians who handle sensitive mental health information. The platform pairs documentation support with practical safeguards, so care teams can move faster without treating client data casually.

Last reviewed July 2026. Security details are available for practice review.

HIPAA compliant for covered clinical workflows

ePHI is encrypted in transit and at rest, access is role-based and audit-logged, and PHI is only ever processed by vendors under a signed BAA.

Built for HIPAA

Safeguards and BAAs for covered clinical workflows.

BAA available

Business Associate Agreement available for eligible organizations.

No AI training

Clinical data is not used to train AI models.

Encrypted

Data is protected in transit and at rest.

Access controls

Clinical records are limited to authorized users.

Review ready

Security details are available during practice review.

Privacy commitments that clinicians can explain to clients.

Clinical data does not train AI models

Miwa does not use client notes, transcripts, assessments, treatment plans, or protected health information to train AI models.

Sensitive data stays in clinical workflows

Miwa is designed to keep client information inside the product areas that need it, with safeguards around storage, AI assistance, documentation, and support.

Minimum necessary data is the default

Miwa is built to use the least amount of clinical context needed for a task and avoid placing sensitive information where it does not belong.

Clinicians stay in control

Miwa drafts, organizes, and summarizes. Clinicians review and approve. The platform supports documentation, but it does not replace professional judgment, consent obligations, supervision, or clinical recordkeeping.

Practical safeguards for sensitive clinical work.

Miwa protects client information with layered controls across access, storage, AI assistance, support, and operational review. Practices can request additional security detail during onboarding.

Encryption in transit and at rest

Role-based access controls

Clinical data access limits

Operational logging

Vendor review before clinical use

Incident response process

Data minimization practices

AI training opt-out by design

What we haven't done yet

We are not yet SOC 2 or HITRUST certified.

We'd rather tell you that plainly than imply a certification we don't hold. We'll update this page as independent reviews are completed.

Miwa is a clinical support tool, not a crisis service. Every AI output is a draft the clinician reviews before it's used. Records are stored securely; clinical data never trains AI models.

Direct answers to the questions that matter.

Everything else, we're an email away.

Is Miwa HIPAA compliant?+

Miwa is a HIPAA-covered behavioral-health EHR built for HIPAA: ePHI is encrypted in transit and at rest, access is scoped per clinician with audit logging, and PHI is only processed by vendors under a signed BAA. Miwa is not "HIPAA certified" (no such government certification exists); compliance is shared between Miwa and each clinician.

Do you sign a BAA?+

Yes. Miwa can make a Business Associate Agreement available to covered entities and practices using Miwa for covered clinical workflows.

Does AI train on Miwa data?+

No. Miwa does not permit clinical data or protected health information to be used for AI model training.

Is Miwa's AI a licensed professional?+

No. Miwa's AI is a tool. It is not a licensed health professional, does not provide medical, psychological, or clinical advice, and does not imply that any AI output is the advice, care, report, or service of a licensed professional. Every AI-generated draft is reviewed by the clinician before it enters the chart.

Can Miwa staff access PHI?+

Access is limited to authorized operational needs, such as security, support, or troubleshooting.

Do you sell data?+

No. Miwa does not sell client data, therapist data, session data, transcripts, notes, assessment results, or de-identified clinical datasets.

Do you have SOC 2 or HITRUST?+

Not yet. Miwa does not claim SOC 2 or HITRUST certification. We will update this page as additional independent reviews are completed.

Need a BAA or security review?

Send your compliance questions before using Miwa in a covered clinical workflow. We'll help confirm the right contract and privacy configuration.