SessionSteps

Security at SessionSteps

Last updated: September 20, 2026

Security approach

SessionSteps uses defense-in-depth controls designed for sensitive behavioral-health workflows. Security is a shared responsibility between SessionSteps, practices, and every authorized user.

Platform controls

  • Encrypted HTTPS connections and encryption at rest through managed infrastructure.
  • Role-based access, tenant isolation, database row-level security, and server-side authorization checks.
  • Audit logging for sensitive administrative and clinical-workflow events.
  • Multi-factor authentication support, session controls, and recovery-code safeguards.
  • Secure email delivery through Paubox and payment processing through Stripe.

Healthcare safeguards

SessionSteps is built with HIPAA-conscious security controls. Whether a particular use is HIPAA compliant also depends on the practice's configuration, policies, workforce training, access management, and signed agreements.

Report a concern

Do not include protected health information in a general security report. Use the in-product support channel to report a suspected security issue so it can be triaged promptly.