Home Privacy and security

Privacy and security

How HealOS handles PHI, BAAs, audio and retention.
By Swades Admin
• 2 articles

How HealOS handles PHI

HealOS is built to be used with protected health information. A few facts customers ask for most often: - We sign a Business Associate Agreement with every practice. AI Frontdesk setup asks whether the BAA is signed because that is a precondition of going live, not a formality. Ask support for the current agreement and the compliance documentation pack; HealOS's published posture — HIPAA, SOC 2 Type II, ONC certification and AES-256 encryption at rest — is stated on healos.ai, and the privacy policy at healos.ai/privacy is the controlling document. - Your practice's data is yours. A HealOS practice cannot see another practice's patients, sessions, calls or templates. Inside your practice, a teammate sees what their product access allows, and templates are private unless you mark them Org shared. - Recordings are bounded. Visit audio is used to produce the transcript and the note, and is kept for playback only if you turn on Enable dictation playback. Phone calls are recorded up to the moment a warm transfer connects — nothing after the hand-off is recorded. - You can keep specific text out of notes. The PHI Filter list holds words that must never appear in a generated note — a name, an address, a nickname. - Support sees what it needs, when you ask. When you send us a session or call to investigate, our support engineers look at that record. We ask for patient initials and a timestamp rather than a name for exactly that reason. What to avoid sending us Do not paste a full note, a patient's name or an insurance ID into a chat message or an email to support. Send the patient's initials, the date and time, and the screen you were on. Every session and every call is traceable from that, and it keeps PHI out of a support thread that does not need it. Retention Retention is yours to set — see Audio, notes and retention.

Last updated on Sep 29, 2026

Audio, notes and retention

Sessions and notes By default a session and its note stay until you delete them. To retain less, open Account Settings and turn on Automatically delete sessions, then set Delete after … days — anything from 1 to 90. Set it to match your practice's own records policy rather than leaving it at the maximum. Auto-deletion applies from the moment you turn it on. It does not retrospectively remove what is already older than the window in the same instant — give it a cycle, and tell us if you need a bulk cleanup of historic sessions. Audio Visit audio is used to produce the transcript and the note. It is kept for playback only if Enable dictation playback is on, which is off by default — and you need the patient's consent to store audio. Turning playback off stops new audio being retained. Deleting by hand A deleted session goes to Deleted Notes (the recycle bin), where you can restore it or remove it permanently. Permanent deletion is what it says. Phone calls Call recordings, transcripts and summaries live under Inbound Calls for the AI receptionist. The recording stops when a warm transfer connects. Faxes and documents A fax stays in the inbox with its extracted data and its PDF. Filing it to the chart copies it into the EHR; deleting the referral built from it does not delete the fax itself. Getting data out, or getting it removed Ask support for an export — notes, transcripts and call records can be provided — and do it while the account is active rather than after cancellation. For a deletion request covering a specific patient, or a whole account, write to us with what has to go and we will confirm in writing when it is done.

Last updated on Sep 29, 2026