HIPAA on the platform
How HIPAA flows through the Heartful Sprout product, plus the Notice of Privacy Practices patients receive at onboarding.
Notice of Privacy Practices
The Notice of Privacy Practices (NPP) is the formal HIPAA document patients receive at onboarding. It explains what protected health information is collected, how it can be used or shared, and the patient's rights.
Two formats available — same content, different presentation:
- Notice of Privacy Practices — visual (PDF) — patient-friendly graphic layout, best for handing to families
- Notice of Privacy Practices — detailed text (PDF) — full legal text with patient signature line
Effective date: April 28, 2025.
Patient rights at a glance
The NPP gives patients the right to:
- Get an electronic or paper copy of their medical record
- Ask to correct their record
- Request confidential communications
- Ask to limit what's used or shared
- Get a list of disclosures
- Choose someone to act for them
- File a complaint without retaliation
How the platform uses or shares PHI
Standard HIPAA-permitted uses:
- Treatment — sharing with other professionals who are treating the patient
- Operations — running the practice, improving care, contacting patients
- Billing — to health plans and other payers
Plus disclosures governed by law (public health, research, law enforcement, organ donation, court orders, etc.). The NPP enumerates each.
Consent flow on the patient app
When a patient enters your invite code, the app shows a consent screen summarizing what will share back to you (tracking data, growth measurements, milestones, and health records) with an explicit authorization checkbox. For details and revocation rules, see Connecting patients → HIPAA consent.
PHI handling on the platform
- Dictation audio streams directly to the transcription service (Deepgram) over an encrypted connection and is not stored by the platform; only the transcript is saved with the session.
- Session PDFs, billing documents, and patient records are stored encrypted.
- Access is gated by organization and per-patient permissions.
PHI rule. Don't share patient health information directly with individual Heartful Sprout team members. Use support@heartfulsprout.com — it's the HIPAA-aware channel.
What families consent to in the app
After entering your invite code, the family is shown an explicit consent screen listing every category of data that will share back to you.
What the family consents to share
- Feeding logs (breast, bottle, pumping)
- Sleep logs and patterns
- Diaper logs
- Growth measurements and percentiles
- Developmental milestones
- Vaccinations, doctor visits, medications
- Temperature readings
- Food introduction and allergy tracking
- (plus app-specific items unique to Heartful Sprout or Heartful Baby)
Consent semantics
- Per patient app. Consent in Heartful Baby doesn't auto-grant in Heartful Sprout — each app has its own consent step.
- Revocable. The family can soft-disconnect from their app, which stops new data from flowing. Existing data stays on your end.
- Multi-provider. A family can connect to multiple clinicians on the same patient record.
This page covers the in-app consent step. For the Notice of Privacy Practices and how the platform handles protected health information, see HIPAA on the platform.
Data flows
What moves between the patient apps and the Clinician Platform. The Program Access panel shows this same matrix per patient — see The Program Access panel.
Patient app → Clinician Platform
When a family is connected and has given HIPAA consent:
| Record | Source app | Where it appears |
|---|---|---|
| Growth measurements & percentiles | Heartful Sprout + Heartful Baby | Trends → Growth |
| Meals, bottles, reactions, intake | Heartful Sprout | Trends → Nutrition |
| Feeds, diapers, sleep, temperature, medications | Heartful Sprout + Heartful Baby | Trends → Infant Tracking |
| Food introduction & allergens | Both apps | Trends → Infant Tracking and Trends → Nutrition |
| Developmental milestones | Heartful Baby | Trends → Milestones |
| Vaccination records | Heartful Baby | Care Plan → Vaccines |
| Check-ins, screeners, home practice | Eating Recovery | Trends → Eating Recovery, Summary → Safety Flags |
| Messages | Family's app | Messages tab |
Each detail view prints its source ("Synced from the Heartful Baby app").
Some Heartful Baby data stays app-side and reaches you only via the family's exported Clinician PDF: doctor visits and mom wellness don't sync to the platform.
Clinician Platform → Patient app
When a family is connected and the session is signed:
| Data type | Where it appears in the app |
|---|---|
| Session notes for patients | Heartful Sprout → Health → Doctor's Notes |
| Prescribed meal plans & nutrition goals | Heartful Sprout |
| Assigned handouts, routines, screeners | Family's app |
| Session Summary PDF |
Record-only patients
- No programs on means no data flows either direction.
- Turn a program on later from Settings → Program Access when the family is ready.
Retention & deletion
Privacy controls differ per patient app; Clinician Platform retention follows medical-record norms.
Patient-side controls
| Control | Heartful Baby | Eating Recovery | Heartful Sprout |
|---|---|---|---|
| Data export | Machine-readable JSON of all app records | — | — |
| Account deletion | Two-stage confirmation, then immediate permanent delete | Scheduled 30 days out; family can cancel by signing back in | Contact support |
| Usage analytics toggle | Opt out of telemetry separately from deletion | — | — |
What you see when a family deletes
For Eating Recovery families, the patient's Program Access shows a Deactivated chip with the deletion state: scheduled deletions note the date and pause new check-ins; completed deletions note that everything already shared stays in your record.
Clinician-side retention
- Patient records are retained according to your jurisdiction's medical-records retention rules.
- Archived patients stay in the platform for documentation and billing purposes.
- A family deleting their app account does not remove data already shared into your record.
- For full deletion of a patient record, contact support@heartfulsprout.com.
Specific retention windows by jurisdiction coming soon.