Skip to main content

Data governance and access controls

Learn how Allia uses data agency, separates clinical and administrative data, and controls access for privacy and compliance.

Allia Health is designed around data agency. It separates clinical data from administrative account data to support privacy and regulatory compliance.

How data is classified

Clinical data (zero-access encryption)

Clinical data includes content related to patient treatment and clinical documentation:

  • Therapy session transcripts and generated notes

  • Treatment plans and progress documentation

  • Clinical assessments and diagnostic records

All clinical data is encrypted at the source. Allia Health does not possess the decryption keys required to view or access this information. Access is restricted exclusively to the authorized clinician.

Account data (administrative access)

Account data includes information needed to operate the EHR:

  • Clinician and patient contact information

  • Billing and payment processing details

  • Scheduling and appointment metadata

Allia Health personnel may access administrative data strictly for support, billing, and system maintenance. This access is governed by the "minimum necessary" standard.

Clinical data ownership and portability

Providers maintain full authority over the lifecycle of data stored in Allia Health.

  • Manage data: Clinicians can create, update, or delete records in the platform at their discretion.

  • Delete records: When a clinician deletes a record, it is removed from the primary production database.

  • Get administrative support: The Allia Health support team can help with data management tasks. The team remains technically unable to view the content of encrypted clinical files during support.

Get help

For help with data management or account configuration, contact the Support Desk at support@allia.health.

Did this answer your question?