For Therapists & Healthcare Professionals

HIPAA-safe AI by architecture, not by promise.

Hey Eduardo runs entirely on your Mac. PHI never leaves your device. There is no third party to sign a BAA with — because there is no third party receiving client data. The HIPAA question becomes structurally moot.

The Problem

Most AI tools create HIPAA risk the moment you paste in a session note.

Consumer ChatGPT, Claude.ai, and Gemini retain inputs by default. For a covered entity, that's a third-party disclosure of PHI without a Business Associate Agreement — a textbook HIPAA breach.

Third-party PHI disclosure

Pasting session notes, intake forms, or any patient-identifying information into ChatGPT or Claude.ai constitutes a disclosure to a third party without a BAA — a HIPAA violation.

BAA evaluation burden

Even enterprise AI tools require careful BAA negotiation, contract review, and ongoing vendor oversight. Most solo and small-group practices don't have time or legal support for this.

Proposed HIPAA Security Rule updates

HHS OCR proposed the first major HIPAA Security Rule update in 20 years (January 2025), citing the rise of AI tools and ransomware. New standards favor data-minimization architectures.

The Solution

No transmission, no disclosure, no BAA required.

Hey Eduardo runs the AI model on your Mac. When you paste in a session note, ask about a treatment approach, or draft a referral letter, the PHI is processed by your local hardware. It is not sent to any server. It is not stored by any vendor. It is not used to train any model.

The HIPAA analysis becomes structurally simple: there is no third party receiving PHI, so the rules governing PHI disclosure to third parties do not apply. The Business Associate Agreement question becomes moot because there is no business associate.

Important disclaimer: Hey Eduardo is a productivity tool, not a clinical decision-making system. It does not replace clinical judgment, supervision, or your professional obligations. Use it as you would any other note-taking or research aid — with full professional responsibility for the work product.
✓ Local AI model on your Mac
✓ PHI never leaves your device
✓ No BAA needed (no third party)
✓ No vendor with retention obligations
✓ Works offline (no network exposure)
✓ Sessions cleared on app close
✓ One-time purchase from $49
What You Can Do

Real use cases for clinical practice.

Progress note drafting

Type or paste raw session notes. Ask Eduardo to format them into SOAP, DAP, or your preferred structure. Review and edit before saving.

Treatment plan support

Discuss diagnostic considerations, evidence-based interventions, and treatment plan formats without sending case material to a third party.

Reading research and CE materials

Paste in journal articles, CE course materials, or DSM-5 sections and ask for plain-language summaries. Stay current without overwhelming your reading list.

Common Questions

What clinicians ask before they switch.

Is Hey Eduardo HIPAA compliant?

Because Hey Eduardo runs entirely on your Mac and PHI never leaves your device, there is no data transmission to evaluate and no BAA needed. The architectural protection is stronger than any contractual one.

Do I need a Business Associate Agreement?

No. BAAs are required when sharing PHI with a third-party service provider. Hey Eduardo doesn't receive PHI — it processes everything on your local device.

Can it integrate with my EHR (SimplePractice, TheraNest, etc.)?

Not directly. Eduardo reads text you highlight from any application. Copy a note from your EHR, paste it into Eduardo, and ask. The EHR data stays in the EHR; the Eduardo conversation stays on your Mac.

What happens to my conversations when I close the app?

Conversation history lives in memory only. Close Eduardo and it's gone — no log files, no history stored on disk. By design.

The HIPAA story you can defend in five seconds.

One-time purchase from $49. 14-day money-back guarantee. Apple Silicon Macs only.