Compliance
Behavioral health carries some of the toughest confidentiality law in healthcare. Greenbar works through the scope and applicability of each relevant framework before scaling into a new specialty — and says plainly when that work is still a draft pending legal sign-off, rather than dressing it up as a finished certification.
The relationship
Every practice using Tahlk signs a Business Associate Agreement and EULA with Greenbar Systems before real patient use — this is the contract that makes everything below enforceable, not just described.
Under HIPAA, Greenbar Systems — not Anthropic — is the practice's Business Associate. Your BAA is with Greenbar. You never need a separate agreement with Anthropic, and you never hold your own Anthropic account or key.
Note generation will not run without a signed BAA/EULA acknowledgment on file — this is checked in code before any transcript is sent, not just described in a policy document. Revoking the acknowledgment blocks further note generation immediately.
Framework by framework
These are Greenbar's own working determinations, produced as part of an internal compliance review — not final legal opinions. Every one below is labeled that way, and every one is revisited as the product and its customer base change.
Federal confidentiality protection for substance-use-disorder treatment records.
Part 2 applies to organizations that hold themselves out as providing SUD diagnosis or treatment. Tahlk's current base — podiatry and general behavioral-health/psychiatry practices — does not meet that threshold today, even though some note templates may incidentally capture substance-use history as one data point in a broader encounter.
Revisited if: Greenbar begins onboarding customers that are themselves dedicated SUD/MAT programs or similar federally-assisted SUD-specialty providers.
Breach-notification duties for vendors of consumer-facing personal health records.
The rule targets products with a patient-facing account or personal health record that the patient directly controls. Tahlk has no patient login, portal, or account of any kind — every interaction is clinician-controlled — so the rule does not reach Tahlk's current product model.
Revisited if: any patient-facing feature is ever added — a portal, patient-accessible notes, or a patient-controlled login.
State laws (California, Illinois, New York, and others) that protect mental-health records more strictly than HIPAA alone.
Several states require specific written patient authorization — beyond a general treatment consent or a business-associate arrangement — before mental-health information can be disclosed to a third party for processing. Because Tahlk sends behavioral-health transcripts to Anthropic via Greenbar's managed proxy, this is an active area of legal review, not a settled one.
Revisited by: counsel licensed in each state where a practice operates — these statutes vary enough that a single national answer isn't accurate.
A newer wave of state laws (Washington's My Health My Data Act, Nevada SB 370, Connecticut) regulating "consumer health data" specifically, including mental- and behavioral-health information.
These laws generally exempt PHI handled by a HIPAA covered entity or business associate consistent with HIPAA — but the exemption isn't automatic, and Washington's law in particular carries a private right of action. Greenbar is working through applicability state by state as the product scales.
Revisited as: Tahlk's footprint grows in states covered by these statutes.
Each framework above reflects Greenbar's own working analysis, done as part of building the product responsibly — not a certification, and not a substitute for your own counsel's review. We'd rather show you the reasoning and its current status than publish a confident-sounding claim we can't back up. If your practice has specific compliance requirements, bring them to the BAA/EULA conversation before you onboard.
Talk to us before you sign — we'd rather answer them now than after your BAA is in place.