Unblend.me, HIPAA & PHI: A Secure Digital Space for Your Internal Family

Unblend.me, HIPAA & PHI: A Secure Digital Space for Your Internal Family
By Ilana GershteynNovember 21, 20258 min read
Security & Privacy#HIPAA#IFS Therapy+3

Overview

Your IFS work is deeply personal. Here's how Unblend.me keeps your Parts, your healing, and your PHI protected with rigorous HIPAA compliance.

With Unblend.me, accessing Internal Family Systems (IFS) therapy becomes more flexible, more personal, and more immediate. You can check in with your Parts from home, in your car before a hard conversation, or wherever your inner world needs attention. But this level of access comes with a profound responsibility: protecting your privacy.

Your IFS work involves some of the most vulnerable, sensitive layers of your psyche. It deserves a digital space that is as safe as a therapist's office. That's where HIPAA comes in—and where Unblend.me's security foundation begins.

What HIPAA Compliance Means at Unblend.me

HIPAA is not optional for us. It's the ethical, legal, and relational backbone of everything we build. Here's how our compliance protects both patients and therapists.

For Patients: Focus on Your Parts, Not Your PHI

  • Peace of mind: Be vulnerable and connect with your managers, firefighters, and exiles knowing the digital room is soundproof. Your focus stays on your inner world, not on the safety of your personal health information (PHI).
  • Confidentiality: Your personal journals, part mapping, voice notes, and every message to your therapist are protected with encryption in transit and at rest.
  • Trust: Healing requires safety. HIPAA compliance is the structure that keeps the space trustworthy as you do deep IFS work.

For Therapists: Protect Your Patients and Your Practice

  • Meet legal obligations: As a Covered Entity, you must use HIPAA-compliant tools and maintain signed BAAs. We provide this automatically.
  • Reduce risk: Non-compliant tools—email, SMS, consumer video apps—create liability exposure, fines, and damaged trust.
  • Uphold ethical standards: Unblend.me strengthens your commitment to confidentiality and client wellbeing.

HIPAA and PHI, Explained Simply

What is HIPAA?

HIPAA (the Health Insurance Portability and Accountability Act) is the U.S. federal law that sets the national standard for protecting sensitive patient health information. It ensures PHI is not shared without consent.

The Most Important Term: PHI

PHI (Protected Health Information) includes any identifiable data related to a patient’s past, present, or future mental or physical health.

  • Obvious examples: name, date of birth, address, Social Security number.
  • Critical examples for IFS work: diagnoses, therapy notes, IFS parts maps, session audio/video, voice uploads, chat logs, and even the fact that someone is a client at a practice.

The Key HIPAA Roles

  • Covered Entity: Your therapist or practice. They hold legal responsibility for protecting PHI.
  • Business Associate: Unblend.me. Because we create, store, and transmit PHI on behalf of therapists, HIPAA requires a Business Associate Agreement (BAA) with strict compliance obligations.

How Unblend.me Achieves HIPAA Compliance

Compliance is not a one-time task—it is an active, ongoing system. Unblend.me follows a three-layer security framework.

Layer 1: Technical Safeguards

  • Encryption: All PHI is encrypted in transit and at rest, ensuring it is unreadable to unauthorized parties.
  • Access controls: Only authorized users—patients, therapists, and their permitted staff—can access PHI. Unblend.me engineers cannot read therapy notes or journals.
  • Audit logs: Every access event is recorded to ensure accountability and detect suspicious activity.

Layer 2: Administrative Safeguards

  • Business Associate Agreement (BAA): A legally required contract in which Unblend.me commits to meeting HIPAA security standards on behalf of therapists.
  • Internal training: All team members undergo annual HIPAA and privacy training.
  • Risk assessments: We perform regular audits to identify and resolve vulnerabilities before they become risks.

Layer 3: Physical Safeguards

  • Secure data centers: We use industry-leading cloud infrastructure with 24/7 monitoring, biometric access controls, and strict physical security.

A Secure Foundation for Healing

HIPAA isn't just a checklist—it's a living commitment. We handle the complexity of technical, administrative, and physical security so you and your therapist can focus on what truly matters: healing, integration, and compassionate connection with your internal system. Whether you're learning what blending is or practicing unblending techniques, your IFS work is protected.

Your parts are welcome here—and they are safe.

For therapists: To review our BAA and security details, visit our Trust Center.

For patients: If you have questions about data protection, please review our Privacy Policy or ask your therapist.