You are about to let software answer your phone. Here is exactly what happens to what it hears.
Written for a dentist, not a lawyer. The legal documents are linked at the bottom if you want them.
What HIPAA means for this product
When a patient calls and says their name, their date of birth, and why their tooth hurts, that is protected health information. From the second our system hears it, we are handling PHI on your behalf, which makes us a business associate under HIPAA.
That is not a checkbox. It means we are legally bound to safeguard that information, to use it only to provide the service you hired us for, to tell you promptly if it is ever exposed, and to hold our own vendors to the same standard in writing.
It also means the responsibility does not transfer away from you. You remain the covered entity. What a BAA does is make our obligations enforceable, so that the trust you extend to us has something behind it.
We sign a BAA. Here is what that means for you.
- We only use what we hear to run your receptionist — never to sell, never to advertise, and never to train a general-purpose model.
- If PHI is ever exposed, we notify you without unreasonable delay, and we tell you what was affected rather than issuing a vague statement.
- Every subprocessor that could touch PHI has signed a BAA with us before we send them anything.
- When you leave, we return or destroy your data — your choice — and confirm it in writing.
What every caller hears, before anything else.
This plays at the start of every single call. It cannot be turned off, shortened, or moved later in the conversation — not by you, and not by us.
Mandatory, on every call
“Thank you for calling Cedar Ridge Family Dental. This call is recorded, and you're speaking with an AI assistant.”
Female · General American · Warm, unhurried. Our default.
Sample audio is not bundled with this build, so playback is disabled here. In the product this plays the real render of the line.
Why it is not optional
Eleven states — California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania and Washington — require all parties to consent before a call is recorded. Massachusetts is the strictest of them.
Separately, a growing list of states now requires disclosure when a caller is speaking with an AI rather than a person. California’s bot disclosure law and Utah’s AI disclosure requirements are the ones most practices encounter first.
Rather than maintaining a per-state configuration that a practice could get wrong, we announce both things on every call in every state. It costs about four seconds. In our experience patients mind it far less than being sent to voicemail.
How the data is actually protected.
Encrypted in transit and at rest
TLS 1.2 or better on every connection, including the media stream carrying call audio. Data at rest is encrypted with AES-256. Call recordings and transcripts sit in storage that is encrypted with keys we rotate.
Separated by practice
Every record in our database is scoped to one practice, and that scoping is enforced in the data layer rather than remembered by each screen. We have an automated test that sweeps every list endpoint and fails the build if a new one is added without it.
Access is logged
Every read of a call recording, transcript, or patient detail is written to an audit log with who, what, and when. You can request your practice's audit log at any time, and we will send it as a CSV.
You hold the keys to your PMS
For Open Dental, the Customer API Key is generated by you inside your own system, and you can revoke it instantly without contacting us. We never receive your Open Dental password and cannot log into it.
Retention you control
You choose how long call recordings and transcripts are kept — from 30 days to seven years. When the window closes, the recording is deleted automatically and the deletion is recorded in the audit log.
Export and deletion on request
Ask and we will export everything we hold for your practice as JSON and CSV, usually within two business days. Ask us to delete it and we will, and confirm in writing when it is gone.
Everyone who could touch your data.
Published openly, because you cannot assess a vendor whose own vendors are a secret. We give 30 days notice before adding one.
| Subprocessor | What they do | Location | BAA signed |
|---|---|---|---|
| Google Cloud (Vertex AI) | Speech recognition and language model inference | United States | Signed |
| Twilio | Telephony and SMS delivery | United States | Signed |
| Amazon Web Services | Application hosting, database, and encrypted storage | United States (us-east-1) | Signed |
| Stripe | Payment processing (no PHI) | United States | No PHI |
| Sentry | Error monitoring (PHI scrubbed before transmission) | United States | Signed |
| Postmark | Transactional email to practice staff (no PHI) | United States | No PHI |
“No PHI” means that subprocessor is structurally unable to receive protected health information — Stripe sees a practice name and a card, never a patient. Where a vendor could conceivably see PHI, we have a signed BAA regardless of how unlikely it is.
Where we actually stand
- HIPAAIn place
- Compliant, with a signed BAA available before you connect anything. This is the one that governs your patients' information.
- SOC 2 Type IIIn progress
- In progress. Our observation window closes in Q1 2027. We will not claim it before the report is issued, and we are happy to share the auditor's name now.
- HITRUSTNot pursued
- Not pursued. It is expensive and slow, and for a practice of your size it would not tell you anything the BAA and SOC 2 do not.
Security question we have not answered here? security@dentelo.com
Read the BAA before you sign anything.
We would rather you read it now than discover a surprise in month three. Ask us anything, and we will answer it in writing.
No contract. Month to month. Cancel from the billing page.