Compliance Posture

Patient privacy isn't an add-on here.
It's how the thing was built.

Most AI vendors charge extra for HIPAA compliance, or hide it behind an enterprise sales call. We built it in from the start, at every price, with no upcharge. This page is for you and for your attorney. It says what's finished and what's still in progress — because you'll find out either way, and we'd rather you find out here.

In plain English

What actually happens
to your patients' information.

Your patients' conversations are never used to train AI. Some vendors feed call recordings into AI systems that learn from them. We don't, and it isn't a policy we could quietly change — the system has no path to do it.

We keep a record of every time patient information is accessed. Every call, every booking, every look at a record — logged with a timestamp. If anyone ever asks who saw what and when, there's an answer.

Text messages to your patients never mention treatments. A confirmation text says the date, the time, and your practice's name. Never "Botox" or "filler" or anything about their treatment. That's deliberate: it keeps your patients' text messages from becoming medical records sitting on a phone.

The AI won't discuss anything medical. It can't recommend a treatment, quote a procedure price, or answer a clinical question. It books a consult instead. Built in, not a setting.

Everything is encrypted, moving between systems and sitting in storage.

Who else is involved

Every company that touches your patients' information
— and what agreement we have with each.

Delivering this service means a handful of specialized companies are involved. HIPAA requires a signed agreement with each one that handles patient information. Here's the complete list and where each one stands.

What they do Company Where it stands
Powers the voice conversation Retell AI Signed agreement, July 2026. Independently security-audited.
Sends you booking notifications Amazon Web Services Signed agreement, July 2026.
Our internal email and documents Google Workspace Signed agreement, July 2026.
Stores your bookings and patient records Xano Agreement activated before we process any patient information. No patient data goes in before it's in place.
Phone line and text messages Twilio No agreement needed — by design. Because appointment texts never contain treatment information, they aren't medical records. If your practice needs texts that do mention treatments, we put an agreement in place before turning that on.
Our website Vercel No agreement needed. It never sees patient information.

We'll send you this list on request, and it's part of the agreement we sign with you. If we ever add a company that will handle patient information, you hear about it before it happens.

California

Built around the rules
that took effect in January.

California tightened oversight of medical aesthetic practices in 2026. Those rules govern clinical practice, not AI specifically — but they shape what an AI front desk can safely do. Here's where ours stops.

No treatment recommendations

Ever, to anyone, under any phrasing.

No procedure pricing

Pricing for medical procedures goes through a consult with your provider.

Never issues patient-specific orders

That stays with your supervising physician.

Recording disclosure on every call

As California's two-party consent law requires. Verified in our own live call records — not just written into the agent's instructions.

What's still in progress

We're pre-launch,
and this page says so.

You're reading this before we have a hundred customers. Some of the formal documentation that comes with maturity is still being written. Here's exactly where each piece stands:

In progress

The agreement we sign with you (the BAA)

With our attorney now. Signed before we handle any patient information, and available for your attorney to read before you commit to anything.

In progress

Written security risk assessment

Finished before our first practice goes live.

In progress

Written policies

Who can access what, how devices are handled, how information moves.

In progress

What we do if something goes wrong

Our incident and notification procedure.

In progress

Backup and recovery plan

Tested before launch.

If any of these matter to your decision, ask and we'll tell you exactly where it is. A vendor who tells you everything is finished, at our stage, isn't being straight with you.

Questions worth asking anyone

Five questions that separate
serious vendors from the rest.

Ask us. Ask whoever else you're talking to.

1

Will you sign a BAA with my practice, and can my attorney see it first?

Without that agreement, no vendor can legally handle your patient information. Full stop.

2

Which other companies touch my patients' data, and do they all have agreements too?

One gap anywhere in the chain breaks the whole thing.

3

Where is my patient data stored, and what happens to it if I leave?

Which company, which country, how long they keep it, and how it gets deleted.

4

If there's a breach, how fast do I hear about it — in writing?

Ask about their commitment to you and their vendors' commitment to them. Those are often very different numbers, and a vendor who hasn't read their own contracts won't know theirs.

5

Can the AI be talked into giving medical advice?

Ask them to demonstrate it. Try to talk their AI into recommending a treatment. If it does, that's your license on the line.

Our answer to #4, since we're asking you to ask it

We commit to notifying you in writing within five business days of confirming a breach. Our voice vendor's contract gives them up to 21 business days to notify us. We think you should know both numbers.

Have your attorney call us.

Getting this right
is a conversation, not a checkbox.

We'll walk through any of this, share our draft agreement when it's ready for review, or get on a call with your counsel directly.

Call us · (951) 418-2579