How HealOS handles PHI
HealOS is built to be used with protected health information. A few facts customers ask for most often:
- We sign a Business Associate Agreement with every practice. AI Frontdesk setup asks whether the BAA is signed
because that is a precondition of going live, not a formality. Ask support for the current agreement and the
compliance documentation pack; HealOS's published posture — HIPAA, SOC 2 Type II, ONC certification and AES-256
encryption at rest — is stated on healos.ai, and the privacy policy at healos.ai/privacy is the controlling
document.
- Your practice's data is yours. A HealOS practice cannot see another practice's patients, sessions, calls or
templates. Inside your practice, a teammate sees what their product access allows, and templates are private unless
you mark them Org shared.
- Recordings are bounded. Visit audio is used to produce the transcript and the note, and is kept for playback only if
you turn on Enable dictation playback. Phone calls are recorded up to the moment a warm transfer connects — nothing
after the hand-off is recorded.
- You can keep specific text out of notes. The PHI Filter list holds words that must never appear in a generated note
— a name, an address, a nickname.
- Support sees what it needs, when you ask. When you send us a session or call to investigate, our support engineers
look at that record. We ask for patient initials and a timestamp rather than a name for exactly that reason.
What to avoid sending us
Do not paste a full note, a patient's name or an insurance ID into a chat message or an email to support. Send the
patient's initials, the date and time, and the screen you were on. Every session and every call is traceable from that,
and it keeps PHI out of a support thread that does not need it.
Retention
Retention is yours to set — see Audio, notes and retention.