HIPAA Compliance

Protecting Patient Information is Our Highest Priority

Dental practices trust Annie to communicate with patients, manage appointments, and streamline front desk operations. That trust starts with protecting patient information.

Annie is designed with security and privacy at its core. We build our platform to help dental practices safeguard Protected Health Information (PHI) while supporting compliance with the Health Insurance Portability and Accountability Act (HIPAA).

Our goal is simple: give practices the confidence to use AI without compromising patient privacy.

How Annie Supports HIPAA Compliance

While no software alone can make an organization HIPAA compliant, Annie is built to help practices meet their compliance obligations through secure technology, privacy-focused design, and operational safeguards.

Our platform includes security features such as:

  • Encryption of data in transit using industry-standard TLS protocols

  • Encryption of sensitive data at rest

  • Role-based access controls

  • Authentication and secure account management

  • Audit logging and system monitoring

  • Secure cloud infrastructure

  • Ongoing security updates and vulnerability management

  • Principle of least privilege for internal access to customer data

Business Associate Agreements (BAAs)

Because Annie may process Protected Health Information on behalf of covered entities, we offer Business Associate Agreements (BAAs) to eligible customers.

Our BAA clearly defines our responsibilities regarding the protection, handling, and safeguarding of PHI.

If your practice requires a signed BAA before implementation, our team can provide one during onboarding.

Secure AI Built for Healthcare

Unlike general-purpose AI tools, Annie is purpose-built for dental practices.

Our AI is designed to:

  • Handle patient conversations securely

  • Protect sensitive information throughout workflows

  • Minimize unnecessary exposure of PHI

  • Support healthcare-specific communication needs

Security and privacy considerations are incorporated into product development as new features are released.

Employee Security Practices

Technology is only one part of protecting patient information.

Our team follows internal security practices designed to help protect customer data, including:

  • Security and privacy training

  • Access controls based on job responsibilities

  • Authentication requirements

  • Confidentiality obligations

  • Incident response procedures

  • Ongoing security awareness

Infrastructure Security

Annie utilizes modern cloud infrastructure designed for reliability and security.

Our infrastructure includes safeguards such as:

  • Network security controls

  • Continuous monitoring

  • Regular backups

  • High availability architecture

  • Disaster recovery planning

  • Automated security updates where appropriate

Your Role in HIPAA Compliance

HIPAA compliance is a shared responsibility.

While Annie provides secure technology and operational safeguards, healthcare organizations remain responsible for:

  • Proper user access management

  • Employee HIPAA training

  • Internal privacy policies

  • Appropriate use of patient information

  • Compliance with applicable federal and state regulations

We encourage every practice to review its own compliance policies regularly.

Frequently Asked Questions

Is Annie HIPAA compliant?

Annie is designed to support HIPAA compliance through secure infrastructure, encryption, access controls, and privacy-focused operational practices. Healthcare organizations remain responsible for their own compliance programs and internal policies.

Does Annie sign a Business Associate Agreement (BAA)?

Yes. Annie offers Business Associate Agreements (BAAs) for eligible customers.

Is patient data encrypted?

Yes. Data is encrypted both in transit and at rest using industry-standard encryption technologies.

Who can access our data?

Access is limited to authorized personnel with a legitimate business need and is governed by internal access controls and security policies.

Does Annie use patient data to train AI models?

Patient data is handled according to our contractual commitments, privacy policies, and applicable laws. We do not use customer PHI to train general-purpose AI models without appropriate authorization or contractual permission.

(Only keep this statement if it accurately reflects Annie's AI/data practices.)

How is customer data protected?

Annie employs multiple layers of security, including encryption, authentication, access controls, monitoring, and secure cloud infrastructure designed to protect customer information.

What happens if there is a security incident?

Annie maintains incident response procedures designed to investigate, contain, and address security events. Customers are notified as required by applicable agreements and regulations.

Questions About Security?

Our team is happy to answer questions about our security practices, privacy protections, or HIPAA-related documentation.

Contact us →