How we handle PHI, encrypt data, and execute BAAs — in plain English.
Principles
Patient identifiers are hashed (SHA-256) before they leave your systems. We never store raw names, DOBs, or medical record numbers in our application layer. Inquiry intent is classified; identity is discarded.
Any message classified as MEDICAL_QUESTION is locked from AI response and routed to your licensed staff. We never generate medical advice, differential diagnoses, or treatment recommendations.
Transcripts, routing rules, briefs, and inquiry logs belong to your clinic. Exportable. Deletable on request. We do not train models on your patient communications.
A Business Associate Agreement is executed during pilot setup — before any patient-adjacent workflow goes live. Standard terms. Reviewed by healthcare counsel.
Infrastructure
No marketing claims. Here’s exactly what runs under the hood.
BAA Process
We send our standard BAA template during pilot setup. Reviewed by healthcare counsel.
Signed by both parties before any patient-adjacent workflow is activated.
Annual review. Updated if your practice structure, EMR, or state regulations change.
We’ll walk through the stack, the BAA, and your specific compliance requirements before you commit to anything.