Compliance & security

Built for PHI from day one.

Protected health information is the first design constraint, not a policy document written after launch. This page is what we hand your compliance team, and we will send the full package under NDA before the first call is answered.

HIPAA compliant Controls mapped to the HITRUST CSF Signed BAAs
The posture

What is true about how we handle your data

Plain statements, so your privacy officer can check them off rather than interpret marketing language.

BAA before anything else

We sign the business associate agreement during discovery, before any access is granted or data moves.

Encrypted in transit and at rest

Modern transport encryption on every integration, and encrypted storage for everything retained.

Least-privilege access

Role-based access, individually attributed. No shared accounts, no standing production access.

Audited data flows

Every integration is documented: what field moves, where it goes, and why it is needed.

Defined retention

Recording and transcript retention set with you, with deletion on the schedule you specify.

Minimum necessary

We request the narrowest data set that answers the call, and nothing beyond it.

Incident response

A documented plan with notification timelines that meet or beat your BAA terms.

Subcontractor control

Any downstream processor is under a BAA and disclosed to you. No surprise fourth parties.

Monitoring and logging

Access and administrative actions logged and reviewable, with alerting on anomalies.

Outbound specifics

Telephony compliance, separately

Outbound to members raises obligations that have nothing to do with HIPAA. We treat them as their own discipline.

Consent basis per attempt

Every outbound attempt is logged with the consent it relied on and where that consent came from.

Calling windows enforced

Federal and state time-of-day restrictions enforced by the dialer, not by policy alone.

Suppression honored

Do-not-call and plan-level suppression loaded before a campaign runs, with on-call opt-outs applied immediately.

Identity verified

Numbers registered to you and signed at full attestation, so the call is provably from your organization.

More detail on branding and STIR/SHAKEN. See outbound calling
Common questions

What your compliance team will ask

Are you HITRUST certified?

Our controls are mapped to the HITRUST CSF and we will share the mapping under NDA. Certification status and current attestation reports are stated in the security package rather than implied here, ask and we will tell you exactly where we are.

Will you sign our BAA rather than yours?

Yes, in most cases. We will redline where a term is operationally impossible, and we do that during discovery rather than at signature.

Are calls recorded, and for how long?

Recording and transcript retention are configured with you, including the option not to retain audio at all. Deletion runs on the schedule you set.

Where is data processed and stored?

Stated explicitly in the security package, including region and any subprocessor. If you have a data residency requirement, raise it in discovery.

Can our auditors review your controls?

Yes. We support security reviews, questionnaires, and reasonable audit rights as part of the agreement.

Is PHI used to train models?

No. Your data is used to handle your calls under your BAA. Any exception would require your explicit written agreement, and we do not ask for one.

Send this to your privacy officer

We will provide the full security documentation package under NDA, before onboarding starts.

Or talk to our team at (866) 680-7870