Security & compliance

A HIPAA compliant answering service, with a BAA on every plan

What we commit to in writing: a signed BAA before go-live, BAAs with every sub-processor that touches PHI, TLS 1.2+ and AES-256 encryption, PHI minimization, a PHI access log kept six years, breach reports within 10 business days and stated retention. Below is exactly how each works and where data is hosted today.

In short: Clinic Answering Service is a HIPAA compliant answering service: a Business Associate Agreement is signed on every plan before the first patient call, sub-processors that touch PHI sign BAAs, PHI is encrypted with TLS 1.2+ in transit and AES-256 at rest, every PHI access is logged and kept six years, breaches are reported to the practice within 10 business days of discovery, and no patient data trains AI models. Trial workspaces run in AWS Mumbai and must hold sample data only; production PHI for US practices is hosted in an AWS US region.
HIPAA CompliantBAA on every planSub-processor BAAsAES-256 at rest, TLS 1.2+ in transitPHI access log kept 6 yearsNo PHI used for model training

Business Associate Agreement

Included on Solo, Practice and Group at no extra cost. The current BAA (version 2026-10) is signed in the app on the Compliance screen, with name, title, practice legal name, time and IP recorded, or on paper on request. It is signed before the first patient call is forwarded. Ask on the contact page for a copy to review first.

Sub-processor BAAs

Every vendor that touches PHI signs a BAA with us before it does: AWS (hosting), the AvanceZone voice and SMS gateway (our group company), and the speech-to-text and language model providers, which must also accept no-training terms. No eligibility clearinghouse is contracted yet; it will be named and under a BAA before live checks start. Email and payment providers receive no PHI.

Call recordings and transcripts

Recording is on by default per phone number and can be switched off. Transcripts and three-line summaries are stored in the Clinic Answering Service database; recording audio is stored with the voice gateway in the same region and opened from the call record. Both sit on AES-256 encrypted storage; insurance member IDs and EHR credentials are also field-encrypted with AES-256-GCM.

Retention and deletion

Default: recordings and transcripts are kept while your workspace is active and deleted 30 days after cancellation; nightly backups roll off after a further 30 days. A fixed period from 30 days to 7 years can be set on request and is written into your order form (self-service controls are planned). Patient deletion requests from the practice are completed within 30 days and logged.

PHI access log

Every patient record view, export and AI read is logged with user, time, IP address and device, kept for six years, viewable on the Compliance screen and exportable as CSV for your compliance officer. A separate audit trail records every create, edit and delete.

Breach notification procedure

Contain, investigate, then report to your named contact by email and phone within 10 business days of discovery, inside HIPAA's 60-day limit. The report states what happened, when, which patients and data were involved and what we have done, and we cooperate with your notices to patients and HHS.

Hosting region, stated plainly

This website and trial workspaces run on AWS in Mumbai, India (ap-south-1), so trials must use sample data only. Production PHI for US practices is hosted in an AWS US region under AWS's BAA, set up before your BAA is signed and calls are forwarded. 99.9% monthly uptime target with encrypted nightly backups.

Who can see PHI

Your staff, by role (owner, office manager, front desk, provider, billing) and location. Our team works from Coimbatore, India and reaches PHI only through the same logged application, only to resolve a support request you raise, under confidentiality obligations and HIPAA training.

PHI minimization

Clinic Answering Service asks only what the task needs: name, date of birth, phone, reason for visit and insurance ID. It does not take card numbers or full medical histories.

Identity checks on every call

Two identifiers (name and date of birth, or phone on file and date of birth) are confirmed before any appointment or coverage detail is read back.

Minimal texts and voicemails

Confirmations go only to the number on file and say no more than the date and time. Behavioral health practices can hide the practice name entirely.

Safe automation

Eligibility read-backs repeat only what the payer's 271 states and never promise payment; urgency routing sends calls to people, never gives advice. Automated outputs support your staff and never replace professional judgement; anything uncertain, failed or flagged goes to a human queue.

Support and incident response

Support Monday to Friday, 9 am to 5 pm US Eastern Time (ET) at info@radiatus.com and +91-9585160363 (India). Urgent incidents: email with URGENT in the subject and call; acknowledged within 4 hours at any time, 1 hour during support hours. Security reports go to the same address and are answered within 2 business days.

Honest AI disclosure

Clinic Answering Service introduces itself as a virtual assistant on every call and transfers to a person whenever the caller asks.

How we build and run Clinic Answering Service

  • Isolation. Every record carries your workspace ID and every query is scoped to it at the data layer, so one customer can never read another's data.
  • Encryption. TLS 1.2+ in transit; encrypted disks at rest; passwords hashed with Argon2id; API keys stored only as hashes.
  • Access control. Roles (owner, admin, staff, viewer) with per-module permissions, session hardening and login throttling with temporary lockout after repeated failed attempts. Two-factor authentication is on the roadmap.
  • Audit trail. Every create, edit and delete is logged with who, when, from where and what changed.
  • Backups. Nightly encrypted backups, kept on a 30-day rolling cycle.
  • Data ownership. Your data is exported for you on request (and much of it is available through the REST API). If you leave, you get a 30-day export window and then your data is deleted.
  • Read more. See our privacy policy, terms of service, the full Clinic Answering Service feature list and pricing.
  • Responsible disclosure. Found a vulnerability? Email info@radiatus.com and we will respond within 2 business days.

Security questions

Where are recordings and transcripts stored, and for how long?

For live US practices, transcripts are stored in the Clinic Answering Service database and recording audio with the voice gateway, both in an AWS US region on AES-256 encrypted storage. By default they are kept while your workspace is active and deleted 30 days after cancellation. A fixed retention period from 30 days to 7 years can be set for your workspace on request and is written into your order form; self-service retention controls are planned. Trial workspaces run in AWS Mumbai and must hold sample data only.

Is patient data used to train AI models?

No. Protected health information from your calls is never used to train public or shared models. Clinic Answering Service processes transcripts under the BAA, for your practice only, and speech and language-model providers are used only under a signed BAA with no-training terms.

Which sub-processors touch PHI?

Hosting: Amazon Web Services (AWS signs a BAA). Voice and SMS: the AvanceZone gateway, our group company, under a BAA, connecting to US telecom carriers. Speech-to-text and language model providers: only under a BAA with no-training terms. Eligibility clearinghouse: none contracted yet; it will be named and under a BAA before live checks start. Email and payment providers receive no PHI. The named list is sent with the BAA.

What happens if there is a breach?

Under the BAA, Clinic Answering Service reports any breach of unsecured PHI to your named contact within 10 business days of discovery, inside HIPAA's 60-day limit, by email and phone. The report covers what happened, the dates, the patients affected and what we have done, and we cooperate with the notices you send to patients and HHS.

What makes an answering service HIPAA compliant?

A HIPAA compliant answering service signs a Business Associate Agreement, encrypts calls and records, limits PHI to what each task needs, logs access and flows the same terms to its sub-processors. Clinic Answering Service does all five on every plan, starting at $149 a month, and the PHI access log can be exported as CSV from the Compliance screen.

Can I get a copy of the BAA before signing up?

Yes. Ask on the contact page and Clinic Answering Service sends the Business Associate Agreement and the sub-processor list for your compliance review before any patient call is forwarded. The same BAA applies to Solo, Practice and Group plans.

Never send a patient to voicemail again.

Ask for a demo and a person replies within one US business day. BAA signed before the first patient call. No long-term contract.