Does The School OT claim HIPAA compliance?
No. The current build is a PII-ready foundation, not a compliance claim. Identified student information stays disabled until the applicable legal posture, vendor agreements, production environment, risk analysis, restore evidence, incident response, security testing, and operating procedures have been reviewed and approved.
Can a new workspace enter student names today?
The application accepts student names and encrypts identity fields for authorized workspace users. That capability is not production approval: the applicable legal, vendor, security, operational, and customer release gates must still be completed.
Who can see a student record?
Owners and supervisor OTRs can oversee records inside their workspace. Treating OTRs and COTAs must have an active assignment to the student. The same boundary is applied to student pages, aggregate views, schedules, sessions, reviews, reports, imports, and exports.
What is encrypted?
Selected identity and care fields are encrypted with AES-256-GCM before database storage, including student identity, clinical notes, participant responses, goal details, consultations, review comments, correction reasons, progress narratives, MFA secrets, and short-lived import snapshots. Production transport encryption and key-management evidence remain release requirements.
Does the scheduler move students automatically?
No. Optimization produces a draft. An authorized user must review and accept it before it becomes the working week. Manual moves run the same server-side constraint checks, and prior accepted versions remain available for restoration.
Are backup, monitoring, and security-test claims included?
Not yet. The repository includes audit review and verification, retention, key rotation, and security tests, but The School OT does not present those as proof of production recovery or ongoing operations. The risk-based release evidence must be completed for the approved environment.
How should we evaluate The School OT for our organization?
Bring your data classification, applicable student-record requirements, user roles, retention rules, supervision policy, identity lifecycle, incident process, and vendor-review checklist. We will map those questions to the implemented controls and identify any remaining approval evidence.