Skip to main content

HIPAA Notice

Last updated: June 5, 2026

Company Information

WobbleTalk is operated by AAR SOLUTIONS GROUP LLC, located at 4803 Lucky Fawn Ln, Richmond, TX 77407, United States.

Who this applies to

Consumer (parent / family) accounts on WobbleTalk are generally not Covered Entities under HIPAA, and the data parents enter for their own children is not Protected Health Information (PHI) by default. When a licensed clinician, school district, or healthcare organization uses WobbleTalk to deliver care, the clinical data they enter is PHI and is governed by HIPAA.

Business Associate Agreement (BAA)

WobbleTalk will sign a Business Associate Agreement with any Covered Entity or Business Associate that uses our Clinical Mode subscription. To request a BAA:

  1. Sign in and visit the Clinical Mode access page.
  2. Submit your professional license and organization details.
  3. Our team counter-signs and returns the executed BAA, typically within 5 business days.

Clinical Mode is enabled on your account only after the BAA is fully executed.

Administrative, physical, and technical safeguards

  • Data encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access control with audit logging of all access to PHI.
  • Annual workforce HIPAA training and confidentiality agreements.
  • Production data hosted on HIPAA-eligible infrastructure under signed BAAs.
  • Secret rotation, automated vulnerability scanning, and a documented incident-response plan.

AI features and PHI

By default, PHI is not sent to third-party AI providers. AI features used in Clinical Mode operate on de-identified data per 45 CFR § 164.514. Each AI interaction is logged in the in-app audit trail (action type, status, and duration only — no PHI is stored in the log).

Patient rights

If you believe your PHI may have been disclosed in violation of HIPAA, or you wish to exercise your rights of access, amendment, or accounting of disclosures, contact your treating clinician first. You may also contact our Privacy Officer at info@wobbletalk.com or file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.

Breach notification

In the event of a breach of unsecured PHI, WobbleTalk will notify the affected Covered Entity without unreasonable delay and no later than 60 days after discovery, as required by 45 CFR §§ 164.400–414.

Contact our Privacy / Security Officer

Email info@wobbletalk.com.