01
HIPAA & protected health information (PHI)
Any system that handles appointment details, health history, or patient identifiers is handling PHI and is designed under HIPAA's Privacy and Security Rule requirements. There is no such thing as a 'HIPAA-certified' product — we build and document safeguards that can support a compliant environment, and compliance itself depends on the full implementation and your practice's operation of it.
02
Business associate agreements (BAAs)
Where a vendor or RSG handles PHI on the practice's behalf, a BAA is executed before any PHI flows. During scoping we map exactly which vendors in the stack touch PHI and confirm each supports a BAA on the plan tier you actually have.
03
Minimum-necessary access
Each workflow is scoped to the least patient data it needs to function — a confirmation sequence needs an appointment time and a phone number, not a chart. Data the automation does not need is data it never receives.
04
Role-based permissions
Access is granted by role: front desk, billing, provider, and administrator each see different views and different data. Permissions are reviewed at implementation and documented so the practice can maintain them after handoff.
05
Encryption in transit and at rest
PHI is encrypted in transit and at rest across the systems we implement. Vendor encryption claims are verified during scoping rather than assumed from marketing pages.
06
Audit logs
Access to patient data and actions taken by the system are logged so there is a durable record of who saw what and what the automation did. Logs support both internal review and the documentation a practice needs if questions ever arise.
07
Secure data retention
Retention periods are defined during implementation to match your policies and applicable requirements — data is kept as long as it must be and not longer. Disposal of PHI follows a documented process, not an ad-hoc deletion.
08
Patient communication consent
Automated texts and calls run against recorded patient consent, honor opt-outs immediately, and follow telemarketing and messaging rules. Consent status lives with the patient record so every campaign checks it before sending.
09
Human review of anything clinical
Anything touching diagnosis, treatment, medication, or clinical judgment is routed to your staff — automation handles scheduling and administrative communication only. Escalation rules are written with your office and tested before go-live.
10
No AI diagnosis or medical advice — ever
The systems we build are prohibited by design from independently providing diagnoses, treatment recommendations, or medical advice, and that boundary is enforced in the system's rules, not left to model behavior. A patient describing symptoms triggers the office's escalation protocol, including your emergency-line instructions.