Patient privacy is built in, not bolted on
Every automation we build handles patient information under HIPAA. Here is exactly what that means for your practice.
Business Associate Agreement
We sign a BAA with every practice before any patient data is touched. No exceptions, no extra charge.
Encryption everywhere
Patient data is encrypted in transit (TLS) and at rest. Credentials and API keys are stored in secured vaults, never in plain text.
Minimum necessary access
Automations only touch the data they need to do their job, such as names, appointment times, and contact info. Access is role-based and logged.
Vetted infrastructure
We build on platforms that support HIPAA-eligible workloads and sign BAAs with subcontractors that handle protected health information.
Breach notification
In the unlikely event of an incident, we follow the HIPAA Breach Notification Rule and notify your practice promptly so you can meet your own obligations.
Compliant patient messaging
Reminder and recall messages are designed to follow HIPAA guidance for appointment communications, and we help you honor patient opt-outs.
Our role as a business associate
Under HIPAA, your practice is the covered entity and DentalFlow acts as a business associate when our automations process protected health information such as patient names, contact details, and appointment data. The BAA we sign defines what we can do with that data, how we protect it, and what happens when our engagement ends, including return or destruction of your data.
What we never do
- Sell or share patient data with third parties
- Use patient data for marketing or model training
- Store clinical records; we only touch scheduling and contact data
- Keep your data after the engagement ends and you request deletion
Questions we are happy to answer
Compliance questions are welcome on the audit call. Bring your office manager or compliance officer, and we will walk through exactly how data flows through your automations before anything goes live.
Or call us at 773.672.2176