Healthcare
Honest about HIPAA.
There is no such thing as “HIPAA certified”, so we won't claim it. Here's what we actually do, and what we expect from you in return.
Why we won't say “HIPAA certified”
HIPAA has no certifying body, no government agency or standards group issues a “HIPAA certified” badge to a vendor. Any company claiming one is marketing, not compliance. What actually exists is a set of administrative, physical and technical safeguards a covered entity and its business associates have to follow, and a Business Associate Agreement (BAA) that makes those obligations contractual. We'd rather explain that plainly and show our work than hand you a badge that doesn't mean anything.
Our role: business associate, not covered entity
Under HIPAA, your practice is the covered entity, the party with the direct relationship to the patient. AutomateLine acts as your business associate: we handle protected health information (PHI) on your behalf, strictly to run the calls, bookings and follow-ups you configure, and strictly under the terms of the BAA we sign with you before any PHI reaches a system we operate.
What we do for healthcare clients
- Sign a Business Associate Agreement before any PHI reaches a system we operate, and require the same from every subprocessor that touches PHI on the call path.
- Encrypt data in transit and at rest, with minimum-necessary access and audit logging on every system that handles a conversation.
- Connect through certified healthcare integration platforms where a practice-management or EHR system is involved, rather than acting as an authorized reseller of any practice-management vendor.
- Never let the agent give clinical advice, it triages, checks availability, and books, and escalates anything clinical, urgent, or ambiguous to a human on your team.
- Limit staff access to PHI to the people who need it to support your account, with access reviewed and logged.
- Keep a written incident-response process and notify you without unreasonable delay if something goes wrong, consistent with the breach notification rule.
- Retain call and message data only as long as your agreement and your own compliance program require, and honor deletion requests.
What we ask of you
You stay the covered entity: you're responsible for your own HIPAA policies, staff training, and for telling us if a workflow needs to change because your compliance requirements changed. We'll build to the BAA and the scope you approve, if you're ever unsure whether something we're proposing needs a BAA update, ask us before it goes live, not after.
Talk to us
If you work in healthcare and want the specifics for your setup, email hello@automateline.com. For the fuller picture on what actually matters (BAAs, encryption, access control), read HIPAA and AI voice agents, or see how this plays out for a practice on Dentistry.
FAIR QUESTIONS
Questions about healthcare data.
Will you sign a BAA?
Yes. A Business Associate Agreement is in place before any protected health information reaches a system we operate, and across every vendor that touches PHI on the call path.
Can the AI give clinical advice?
No. It triages and books, checks availability, answers policy and logistics questions, and escalates anything clinical to a human. It never diagnoses, prescribes, or advises on treatment, and it identifies itself as AI if a caller asks.
Who else sees the protected health information?
Only the subprocessors named in our BAA that are structurally required to deliver the service, your telephony/voice provider and, where used, a certified healthcare integration platform for calendar or record access. Every one of them is under its own BAA, and we don't add a new subprocessor without updating that agreement.
How long is call data kept, and can it be deleted?
Retention is set in your service agreement, typically only as long as needed to support the workflow, plus whatever your own compliance program requires. You can request deletion of stored PHI at any time, and it's honored unless a legal retention requirement says otherwise.
What happens if there's a breach?
You're notified without unreasonable delay, consistent with HIPAA's breach notification rule, with what we know at the time: what happened, what data was involved, and what we're doing about it. This is written into the BAA, not a verbal promise.
What about non-dental healthcare businesses?
The same process, BAAs, encryption, minimum-necessary access, no clinical advice, applies to any business handling protected health information, not just dental practices.
Where can I read more about how HIPAA and AI actually intersect?
The HIPAA and AI voice agents guide covers what to ask any vendor, in plain language.