Legal

Security

How TuskaMind protects behavioral health data, and what we can share with your compliance team.

Last updated: 2026

Security & Privacy at TuskaMind

TuskaMind is designed for behavioral health organizations handling sensitive client information. Security controls are incorporated throughout the platform, including encrypted communications, role-based access, authentication controls, audit logging, tenant isolation, and secure handling of protected information. Our security practices continue to evolve as the platform and applicable requirements develop.

Encryption

TuskaMind uses encryption to protect sensitive information. The platform enforces HTTPS for data in transit and uses encrypted storage for sensitive application data such as user email addresses, calendar authorization tokens, and other protected fields. TuskaMind also uses hashed tokens where appropriate for secure link validation.

Access control and authentication

TuskaMind uses role-based access controls to limit information and functionality according to a user's authorized role and organization. Authentication includes secure login, one-time verification codes, access and refresh tokens, session controls, and automatic inactivity timeouts. Additional trusted-device controls are being introduced to improve convenience while preserving revocation and audit capabilities.

Audit logging

TuskaMind maintains audit records for security-sensitive, administrative, clinical, financial, and workflow actions throughout the platform. Audit records identify the user or system action, organization, timestamp, and relevant event information. TuskaMind continues to expand audit coverage as new platform features are introduced.

Business Associate Agreements

TuskaMind includes Business Associate Agreements prepared by HIPAA counsel and integrated directly into the platform. This helps practices formalize HIPAA-required responsibilities as part of their onboarding and use of TuskaMind.

Incident response

TuskaMind maintains security and operational controls designed to identify, investigate, contain, and respond to suspected security incidents. Security events may be logged and reviewed, and access credentials or connected services can be revoked or reset when appropriate. Incident-response and notification obligations are handled in accordance with applicable law, contractual requirements, and TuskaMind security procedures.

Reporting a vulnerability

If you believe you have identified a security vulnerability in TuskaMind, please report it promptly to [email protected]. Please do not include client PHI or other sensitive information unless specifically requested through an approved secure channel.

Tenant Isolation

TuskaMind is a multi-tenant platform designed to keep each organization's information logically separated. User permissions and organization context are applied throughout the platform to prevent users from accessing data belonging to another practice.

Secure Integrations

TuskaMind integrations are designed to minimize unnecessary disclosure of sensitive information. For example, external calendar synchronization uses limited appointment information rather than transmitting clinical details, and authorization credentials for connected services are securely managed by the platform.

Questions

Write to [email protected] and we will route your question to the right person.

Empowering healthcare providers with intelligent TuskaMind® solutions for smarter, safer patient care.

Contact Info

24/7 Support Available

For existing customers

© 2026 TuskaMind®. All rights reserved. HIPAA Compliant Behavioral Health Platform.