HIPAA Compliance

Last Updated: February 2026

Overview

The Health Insurance Portability and Accountability Act (HIPAA) sets standards for protecting sensitive patient health information. This page explains how Model Communicator relates to HIPAA requirements and why our architecture is designed to minimize privacy concerns from the ground up.

We Do Not Collect Protected Health Information

Model Communicator is designed so that the content of a user's communication never leaves their device. When a user taps symbols to build a sentence and speaks it using text-to-speech, that entire process happens locally on the device. No utterances, word selections, or communication patterns are transmitted to Model Communicator servers.

Because we do not collect, receive, maintain, or transmit individually identifiable health information, Model Communicator does not handle PHI as defined under HIPAA. This is by design, not by accident. We built Model Communicator this way because we believe the content of someone's communication should be private, always.

What We Store

  • Email address (via Google SSO, if you create an account)
  • Custom grid layouts you create
  • Application preferences (grid size, voice, language)
  • Account authentication tokens

What We Do NOT Store

  • Words or sentences a user speaks
  • Which symbols or tiles a user taps
  • Communication frequency or patterns
  • Voice recordings or audio data
  • Diagnostic or clinical information
  • Health conditions or treatment data
  • Therapist notes or session records

What We Store vs. What We Do Not Store

Client-Side Processing

All communication in Model Communicator is processed client-side, meaning it happens entirely on your device:

  • Text-to-speech uses your device's built-in speech synthesis engine. No audio is sent to external servers.
  • Word prediction runs locally using an on-device vocabulary index. No usage data is transmitted.
  • Synonym suggestions are computed from a local dictionary bundled with the app.
  • Grid navigation is entirely local. We do not track which grids you visit or how often.

For Healthcare Providers

If you are a speech-language pathologist (SLP), occupational therapist, or other healthcare provider using Model Communicator with patients or clients, please be aware of the following:

  • Model Communicator itself does not create HIPAA obligations because it does not handle PHI. However, your own records about patients (session notes, progress reports, treatment plans) remain subject to HIPAA regardless of the tools you use.
  • If you create custom grids that contain identifying information about a patient (for example, a grid labeled with a patient's name), that information would be stored on our servers and should be treated accordingly. We recommend using non-identifying labels for custom grids.
  • Standard obligations under HIPAA apply to your own documentation and record-keeping practices, not to Model Communicator's infrastructure.

iOS SLP Dashboard

The Model Communicator iOS app includes an optional SLP Dashboard feature that allows speech-language pathologists to track aggregated usage summaries for students they work with. This feature uses Apple's CloudKit framework (CKShare) for data sharing between devices.

Important details about the SLP Dashboard:

  • Data sharing uses Apple's CloudKit (CKShare), which is encrypted end-to-end by Apple
  • Only aggregated summaries are shared (such as total communication sessions and grid categories used), not specific words or utterances
  • The SLP Dashboard does not record or transmit the content of any communication
  • Sharing is initiated by the parent or guardian and can be revoked at any time
  • Model Communicator servers never see SLP Dashboard data -- it flows directly between Apple devices via iCloud

Data Encryption

For the limited data we do store (email, custom grids, preferences), we employ industry-standard encryption:

  • In transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher
  • At rest: Data stored in our database is encrypted using AES-256 encryption
  • Authentication: Account credentials are managed by Clerk, which uses industry-standard security practices including bcrypt hashing and secure token management

Business Associate Agreements

Because Model Communicator does not collect, store, or transmit PHI, we do not currently offer Business Associate Agreements (BAAs). A BAA is required under HIPAA when a service provider handles PHI on behalf of a covered entity. Since Model Communicator's architecture ensures that no PHI reaches our servers, a BAA is not applicable.

If your organization has specific compliance questions or needs further documentation about our data handling practices, we are happy to provide additional information. Please contact us.

Contact Us

If you have questions about Model Communicator and HIPAA compliance, or if you need documentation for your organization's compliance review, please contact us:

Email: jim@modelcommunicator.com
Project: Model Communicator
Location: Michigan, USA