Reference
HIPAA & privacy

HIPAA on the platform

How HIPAA flows through the Heartful Sprout product, plus the Notice of Privacy Practices patients receive at onboarding.

Notice of Privacy Practices

The Notice of Privacy Practices (NPP) is the formal HIPAA document patients receive at onboarding. It explains what protected health information is collected, how it can be used or shared, and the patient's rights.

Two formats available — same content, different presentation:

Effective date: April 28, 2025.

Patient rights at a glance

The NPP gives patients the right to:

  • Get an electronic or paper copy of their medical record
  • Ask to correct their record
  • Request confidential communications
  • Ask to limit what's used or shared
  • Get a list of disclosures
  • Choose someone to act for them
  • File a complaint without retaliation

How the platform uses or shares PHI

Standard HIPAA-permitted uses:

  • Treatment — sharing with other professionals who are treating the patient
  • Operations — running the practice, improving care, contacting patients
  • Billing — to health plans and other payers

Plus disclosures governed by law (public health, research, law enforcement, organ donation, court orders, etc.). The NPP enumerates each.

Consent flow on the patient app

When a patient enters your invite code, the app shows a consent screen summarizing what will share back to you (tracking data, growth measurements, milestones, and health records) with an explicit authorization checkbox. For details and revocation rules, see Connecting patients → HIPAA consent.

PHI handling on the platform

  • Dictation audio streams directly to the transcription service (Deepgram) over an encrypted connection and is not stored by the platform; only the transcript is saved with the session.
  • Session PDFs, billing documents, and patient records are stored encrypted.
  • Access is gated by organization and per-patient permissions.

PHI rule. Don't share patient health information directly with individual Heartful Sprout team members. Use support@heartfulsprout.com — it's the HIPAA-aware channel.

What families consent to in the app

After entering your invite code, the family is shown an explicit consent screen listing every category of data that will share back to you.

What the family consents to share

  • Feeding logs (breast, bottle, pumping)
  • Sleep logs and patterns
  • Diaper logs
  • Growth measurements and percentiles
  • Developmental milestones
  • Vaccinations, doctor visits, medications
  • Temperature readings
  • Food introduction and allergy tracking
  • (plus app-specific items unique to Heartful Sprout or Heartful Baby)

Consent semantics

  • Per patient app. Consent in Heartful Baby doesn't auto-grant in Heartful Sprout — each app has its own consent step.
  • Revocable. The family can soft-disconnect from their app, which stops new data from flowing. Existing data stays on your end.
  • Multi-provider. A family can connect to multiple clinicians on the same patient record.

This page covers the in-app consent step. For the Notice of Privacy Practices and how the platform handles protected health information, see HIPAA on the platform.

Data flows

What moves between the patient apps and the Clinician Platform. The Program Access panel shows this same matrix per patient — see The Program Access panel.

Patient app → Clinician Platform

When a family is connected and has given HIPAA consent:

RecordSource appWhere it appears
Growth measurements & percentilesHeartful Sprout + Heartful BabyTrends → Growth
Meals, bottles, reactions, intakeHeartful SproutTrends → Nutrition
Feeds, diapers, sleep, temperature, medicationsHeartful Sprout + Heartful BabyTrends → Infant Tracking
Food introduction & allergensBoth appsTrends → Infant Tracking and Trends → Nutrition
Developmental milestonesHeartful BabyTrends → Milestones
Vaccination recordsHeartful BabyCare Plan → Vaccines
Check-ins, screeners, home practiceEating RecoveryTrends → Eating Recovery, Summary → Safety Flags
MessagesFamily's appMessages tab

Each detail view prints its source ("Synced from the Heartful Baby app").

Some Heartful Baby data stays app-side and reaches you only via the family's exported Clinician PDF: doctor visits and mom wellness don't sync to the platform.

Clinician Platform → Patient app

When a family is connected and the session is signed:

Data typeWhere it appears in the app
Session notes for patientsHeartful Sprout → Health → Doctor's Notes
Prescribed meal plans & nutrition goalsHeartful Sprout
Assigned handouts, routines, screenersFamily's app
Session Summary PDFEmail

Record-only patients

  • No programs on means no data flows either direction.
  • Turn a program on later from Settings → Program Access when the family is ready.

Retention & deletion

Privacy controls differ per patient app; Clinician Platform retention follows medical-record norms.

Patient-side controls

ControlHeartful BabyEating RecoveryHeartful Sprout
Data exportMachine-readable JSON of all app records
Account deletionTwo-stage confirmation, then immediate permanent deleteScheduled 30 days out; family can cancel by signing back inContact support
Usage analytics toggleOpt out of telemetry separately from deletion

What you see when a family deletes

For Eating Recovery families, the patient's Program Access shows a Deactivated chip with the deletion state: scheduled deletions note the date and pause new check-ins; completed deletions note that everything already shared stays in your record.

Clinician-side retention

  • Patient records are retained according to your jurisdiction's medical-records retention rules.
  • Archived patients stay in the platform for documentation and billing purposes.
  • A family deleting their app account does not remove data already shared into your record.
  • For full deletion of a patient record, contact support@heartfulsprout.com.

Specific retention windows by jurisdiction coming soon.