Miwa is designed for clinicians who handle sensitive mental health information. The platform pairs documentation support with practical safeguards, so care teams can move faster without treating client data casually.
Last reviewed July 2026. Security details are available for practice review.
ePHI is encrypted in transit and at rest, access is role-based and audit-logged, and PHI is only ever processed by vendors under a signed BAA.
Safeguards and BAAs for covered clinical workflows.
Business Associate Agreement available for eligible organizations.
Clinical data is not used to train AI models.
Data is protected in transit and at rest.
Clinical records are limited to authorized users.
Security details are available during practice review.
Miwa does not use client notes, transcripts, assessments, treatment plans, or protected health information to train AI models.
Miwa is designed to keep client information inside the product areas that need it, with safeguards around storage, AI assistance, documentation, and support.
Miwa is built to use the least amount of clinical context needed for a task and avoid placing sensitive information where it does not belong.
Miwa drafts, organizes, and summarizes. Clinicians review and approve. The platform supports documentation, but it does not replace professional judgment, consent obligations, supervision, or clinical recordkeeping.
Miwa protects client information with layered controls across access, storage, AI assistance, support, and operational review. Practices can request additional security detail during onboarding.
Encryption in transit and at rest
Role-based access controls
Clinical data access limits
Operational logging
Vendor review before clinical use
Incident response process
Data minimization practices
AI training opt-out by design
We are not yet SOC 2 or HITRUST certified.
We'd rather tell you that plainly than imply a certification we don't hold. We'll update this page as independent reviews are completed.
Miwa is a clinical support tool, not a crisis service. Every AI output is a draft the clinician reviews before it's used. Records are stored securely; clinical data never trains AI models.
Everything else, we're an email away.
Miwa is a HIPAA-covered behavioral-health EHR built for HIPAA: ePHI is encrypted in transit and at rest, access is scoped per clinician with audit logging, and PHI is only processed by vendors under a signed BAA. Miwa is not "HIPAA certified" (no such government certification exists); compliance is shared between Miwa and each clinician.
Yes. Miwa can make a Business Associate Agreement available to covered entities and practices using Miwa for covered clinical workflows.
No. Miwa does not permit clinical data or protected health information to be used for AI model training.
No. Miwa's AI is a tool. It is not a licensed health professional, does not provide medical, psychological, or clinical advice, and does not imply that any AI output is the advice, care, report, or service of a licensed professional. Every AI-generated draft is reviewed by the clinician before it enters the chart.
Access is limited to authorized operational needs, such as security, support, or troubleshooting.
No. Miwa does not sell client data, therapist data, session data, transcripts, notes, assessment results, or de-identified clinical datasets.
Not yet. Miwa does not claim SOC 2 or HITRUST certification. We will update this page as additional independent reviews are completed.
Send your compliance questions before using Miwa in a covered clinical workflow. We'll help confirm the right contract and privacy configuration.