Last updated: June 5, 2026
Company Information
WobbleTalk is operated by AAR SOLUTIONS GROUP LLC, located at 4803 Lucky Fawn Ln, Richmond, TX 77407, United States.
Who this applies to
Consumer (parent / family) accounts on WobbleTalk are generally not Covered Entities under HIPAA, and the data parents enter for their own children is not Protected Health Information (PHI) by default. When a licensed clinician, school district, or healthcare organization uses WobbleTalk to deliver care, the clinical data they enter is PHI and is governed by HIPAA.
Business Associate Agreement (BAA)
WobbleTalk will sign a Business Associate Agreement with any Covered Entity or Business Associate that uses our Clinical Mode subscription. To request a BAA:
- Sign in and visit the Clinical Mode access page.
- Submit your professional license and organization details.
- Our team counter-signs and returns the executed BAA, typically within 5 business days.
Clinical Mode is enabled on your account only after the BAA is fully executed.
Administrative, physical, and technical safeguards
- Data encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control with audit logging of all access to PHI.
- Annual workforce HIPAA training and confidentiality agreements.
- Production data hosted on HIPAA-eligible infrastructure under signed BAAs.
- Secret rotation, automated vulnerability scanning, and a documented incident-response plan.
AI features and PHI
By default, PHI is not sent to third-party AI providers. AI features used in Clinical Mode operate on de-identified data per 45 CFR § 164.514. Each AI interaction is logged in the in-app audit trail (action type, status, and duration only — no PHI is stored in the log).
Patient rights
If you believe your PHI may have been disclosed in violation of HIPAA, or you wish to exercise your rights of access, amendment, or accounting of disclosures, contact your treating clinician first. You may also contact our Privacy Officer at info@wobbletalk.com or file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
Breach notification
In the event of a breach of unsecured PHI, WobbleTalk will notify the affected Covered Entity without unreasonable delay and no later than 60 days after discovery, as required by 45 CFR §§ 164.400–414.
Contact our Privacy / Security Officer
Email info@wobbletalk.com.