Home Privacy and security How HealOS handles PHI

How HealOS handles PHI

Last updated on Sep 29, 2026

HealOS is built to be used with protected health information. A few facts customers ask for most often:

  • We sign a Business Associate Agreement with every practice. AI Frontdesk setup asks whether the BAA is signed because that is a precondition of going live, not a formality. Ask support for the current agreement and the compliance documentation pack; HealOS's published posture — HIPAA, SOC 2 Type II, ONC certification and AES-256 encryption at rest — is stated on healos.ai, and the privacy policy at healos.ai/privacy is the controlling document.
  • Your practice's data is yours. A HealOS practice cannot see another practice's patients, sessions, calls or templates. Inside your practice, a teammate sees what their product access allows, and templates are private unless you mark them Org shared.
  • Recordings are bounded. Visit audio is used to produce the transcript and the note, and is kept for playback only if you turn on Enable dictation playback. Phone calls are recorded up to the moment a warm transfer connects — nothing after the hand-off is recorded.
  • You can keep specific text out of notes. The PHI Filter list holds words that must never appear in a generated note — a name, an address, a nickname.
  • Support sees what it needs, when you ask. When you send us a session or call to investigate, our support engineers look at that record. We ask for patient initials and a timestamp rather than a name for exactly that reason.

What to avoid sending us

Do not paste a full note, a patient's name or an insurance ID into a chat message or an email to support. Send the patient's initials, the date and time, and the screen you were on. Every session and every call is traceable from that, and it keeps PHI out of a support thread that does not need it.

Retention

Retention is yours to set — see Audio, notes and retention.