This is a reference for vendor reviews, not legal advice and not a certification. No agency certifies software against HIPAA or FERPA; vendor badges claiming otherwise are issued by private companies selling assurance products.
The short version. We are not a business associate under HIPAA and we hold no education records under FERPA, because we never receive your client/student records at all. Every obligation that concerns a vendor holding data is not applicable. Every obligation that concerns a device remains with you, because the device is yours.
Which table applies to you: school-employed practitioners read FERPA; a BCBA in private practice or a clinic that bills electronically starts with the HIPAA Security Rule.
HIPAA Security Rule
Relevant when the practitioner is a covered entity, typically a BCBA in private practice or a clinic that bills electronically. School-employed practitioners should read the FERPA table instead.
| Safeguard | Owner | How it is met |
|---|---|---|
| Business associate contracts164.308(b) | Not applicable | We do not create, receive, maintain, or transmit protected health information on your behalf, so there is no business associate relationship to paper. We will sign a statement to that effect for your vendor file. |
| Data backup plan164.308(a)(7)(ii)(A) | Shared | Sightline keeps automatic local snapshots of its database, on by default, retaining the last seven daily ones, and you can take or export one on demand. They sit on the same computer, so your own backup still has to cover the app's data folder for the plan to survive a failed machine. |
| Disaster recovery plan164.308(a)(7)(ii)(B) | Shared | Restore a snapshot from Settings, or export a copy of one to keep off the machine. Sightline refuses a restore it can detect would lose records. Testing the restore is yours. |
| Unique user identification164.312(a)(2)(i) | You | Sightline has no separate login. The identity boundary is the operating system account, which is also what makes the records readable. Give each practitioner their own account and do not share one. |
| Automatic logoff164.312(a)(2)(iii) | You | Sightline does not lock itself after an idle period. Set a short screen-lock timeout at the operating system level. |
| Encryption at rest164.312(a)(2)(iv) | You | Sightline does not separately encrypt its database. Full-disk encryption is what protects it, and it also decides whether a stolen laptop is a reportable breach. On macOS, Sightline checks whether FileVault is on and reports the status in Settings so you can verify it, but it cannot enable it for you. On Windows, confirm BitLocker yourself. |
| Audit controls164.312(b) | Not provided | Sightline does not log record-level access. If your policy requires a trail of who opened which student's record and when, Sightline does not produce one today. This is the safeguard most likely to matter in a strict review, and we would rather you learn it here than after purchase. |
| Transmission security164.312(e) | Shared | The only student data Sightline transmits is between your paired iPhone and your computer after an untethered observation, over an encrypted local Bluetooth link, and the phone keeps its copy until your computer confirms receipt. Everything sent over the internet carries no observation data and travels over TLS. |
| Device and media disposal164.310(d)(2) | You | Deleting a student scrubs the live database. Local snapshots and any files you already exported still hold that data, and the app says so at the moment you delete. Clear those before retiring or reassigning a machine. |
| Risk analysis164.308(a)(1)(ii)(A) | You | Records are stored in the app's database, in its local snapshots, in files you export, and on a paired iPhone during an untethered observation. That is the full inventory to assess. |
| Breach assessment164.400 to 164.414 | You | A lost or stolen device is your incident, and whether the disk was encrypted is central to it. Because we hold no copy, there is no vendor-side breach that could expose your records. |
FERPA
| Obligation | Owner | How it is met |
|---|---|---|
| School official designation99.31(a)(1) | You | Approving the software and documenting it under your annual notification is the district's step. Districts designate a vendor as a school official when the vendor will hold education records. We hold none, so there is nothing to designate. |
| Use limitation99.31(a)(1)(i)(B) | Sightline | We do not use or access student records for any purpose, including advertising, resale, or model training. The AI model was trained on synthetic observation cases we wrote, never on real students' records. |
| Access and amendment rights99.10 to 99.12 | You | The records are in your possession, so responding to inspection and amendment requests is yours. Sightline exports records as PDF or CSV files, generated locally. |
| Retention, destruction, and vendor copies99.31(a)(1)(i)(B) | You | You control the database, the snapshots, and any exports. There is no vendor-held copy to request the deletion of. |
What Sightline does not provide
- No record-level access log. Sightline cannot tell you who opened which student's record and when.
- No in-app user accounts. Access control is the operating system account, so a shared computer account is a shared record set.
- No application-level idle lock, and no separate database encryption. Both are handled at the operating system level.
- No centralized administration. There is no console for a district to manage installs, enforce settings, or pull records across practitioners.
- No control over exports once written. A PDF or CSV you export is an ordinary file, governed by your policies from that point on.
Statement for your vendor file
Ethoseen LLC does not create, receive, maintain, or transmit protected health information or education records on behalf of Sightline customers. Sightline stores observation records locally on customer-controlled devices. Ethoseen operates no server that receives those records and retains no copy of them. Accordingly, Ethoseen is not a business associate under 45 CFR 160.103 and no business associate agreement is required. Ethoseen does not use or access student records for any purpose, including advertising, resale, or model training. Sightline's automatic network connections, enumerated on the security page, carry licensing, update, and model-download traffic only, plus product analytics and crash diagnostics that stay off unless the customer turns them on.
Write to us if you need this signed on letterhead, or send over a vendor security questionnaire and we will complete it against this page.