Our Commitment to Trust, Safety, and Clinical Integrity

Assessment psychology demands rigor, discretion, and precision. At PsychAssist, trust isn't an afterthought - it's the foundation. We know your documentation affects diagnoses, services, legal outcomes, and lives. Every decision we make reflects that responsibility.

We don't just comply. We overbuild.

The Defensible Assessment Documentation Standard

We published the bar we hold ourselves to

Compliance is the floor. The harder question is whether an assessment report produced with machine assistance can be defended, by the clinician who signed it, in a due process hearing, or to a parent who asks how a conclusion was reached.

So we wrote down the six requirements we believe any such system should meet, published them openly, and measure ourselves against them in public.

  1. Provenance Every clinical claim resolves to an identifiable source.
  2. Disconfirmation The evidence that argues against a conclusion is surfaced, not only the evidence that supports it.
  3. Approval Nothing machine-generated enters a record without a logged clinician approval.
  4. Voice The report reads in your voice and follows your standards, because you are the one who signs it.
  5. Auditability Every action carries a timestamp, an actor and a role.
  6. Disclosure AI use is stated in the record itself, not buried in a license agreement.
Read the full standard

Version 1.0 · Free to read, cite or adopt

HIPAA Compliance

HIPAA Compliance

Meeting the highest standards for healthcare data protection

PsychAssist is HIPAA-compliant and operates under signed Business Associate Agreements (BAAs) with:

  • •AWS (data storage & encryption)
  • •OpenAI, Anthropic, Google (model access with data boundary enforcement)

Our own Business Associate Agreement is published in full, including why every vendor that touches patient data needs one, AI tools included. Read the Business Associate Agreement.

Data is encrypted at rest and in transit. Audit logs, access controls, and version tracking ensure every interaction is secure and traceable.

We follow the principle of least privilege across all infrastructure.

Data Ownership & Protection

Your clinical data remains under your complete control

Your data is your data.

No Training on Your Data

We do not train third-party models using your content

No Cross-Sharing

We do not monetize or cross-share data across customers

Full Control

Every field, note, report, or observation remains under your control

You can export your data at any time. No lock-in, no hidden walls.

Model Control & Safety

AI models are tightly constrained and fully transparent

PsychAssist uses large language models from multiple providers to ensure performance and redundancy. But these models never generate content in isolation. We tightly constrain:

  • •Inputs (only structured, clinician-defined data)
  • •Context windows (bounded by case data, workflow logic)
  • •Outputs (reviewable, editable, never auto-sent)

We maintain detailed logs of all model interactions for transparency and traceability.

Documentation Fidelity

Every report maintains clinical accuracy and legal defensibility

You're not writing notes. You're documenting medical, legal, and educational decisions.

Version Tracking

PsychAssist logs every output version

Editable Reports

Report drafts are editable, exportable, and timestamped

Linked Documentation

Stakeholder documents are linked to clinical artifacts

Our platform supports court-admissible reporting and school district documentation standards.

Ethical AI Use

AI serves clinical judgment, never replaces it

We are not a data company. We are not a billing platform. We are not an upsell funnel.

PsychAssist exists solely to support the clinician. We do not hide AI use. We don't hallucinate. We don't overwrite. Every AI-generated element is traceable, reviewable, and overrideable.

We believe AI should serve judgment - not replace it.

Our Principles:

  • •Transparent AI use
  • •No hallucinations
  • •Full traceability
  • •Clinician control
Dr. Chris Barnes
"As a licensed psychologist, I built PsychAssist to reflect the standards I'm held to, because my name, license, and ethics are on the line with every report we generate."

Dr. Chris Barnes

Founder of PsychAssist.ai

Audit & Review

Complete transparency for stakeholders and regulatory compliance

For clinics, institutions, or legal stakeholders:

Full Audit Trail

Complete audit trail of every report

Role-Based Access

Role-based access for staff vs clinician

Export Logs

Export logs, version diff, and data lineage available

We can assist with audit preparation or submit security documentation upon request.

Backups & Exports

Comprehensive data protection and export capabilities

Nightly Backups

Nightly encrypted backups stored redundantly

Full Practice Export

Full practice export available quarterly or on demand

Multiple Formats

PDF, JSON, and CSV options depending on data layer

Questions

Is PsychAssist.ai HIPAA compliant, and will it sign a BAA?
Yes. PsychAssist.ai operates as a HIPAA-compliant platform and signs a Business Associate Agreement with every practice that handles protected health information. The BAA is published in full at psychassist.ai/baa so it can be read before any conversation with sales.
Is patient data from psychological assessments used to train AI models?
No. Data entered into PsychAssist.ai is never used to train third-party models. The clinic owns its clinical data - not the platform and not a test publisher - and export options are available at any time.
How can a psychologist verify what an AI-assisted report was based on?
Every generated statement in PsychAssist.ai carries its source on the sentence: the measure, uploaded document, session note or behavioral observation it came from. An audit trail records every session started and finished and every document verified and approved, with timestamp, user and role, and can be exported.
Does an AI tool used in a psychology practice need a Business Associate Agreement?
If the tool processes protected health information on the practice's behalf, yes. Under HIPAA any vendor handling PHI is a business associate and requires a signed BAA, and general-purpose AI assistants used without one place the clinician, not the vendor, in breach.