HIPAA Compliance
Protecting Patient Information is Our Highest Priority
Dental practices trust Annie to communicate with patients, manage appointments, and streamline front desk operations. That trust starts with protecting patient information.
Annie is designed with security and privacy at its core. We build our platform to help dental practices safeguard Protected Health Information (PHI) while supporting compliance with the Health Insurance Portability and Accountability Act (HIPAA).
Our goal is simple: give practices the confidence to use AI without compromising patient privacy.
How Annie Supports HIPAA Compliance
While no software alone can make an organization HIPAA compliant, Annie is built to help practices meet their compliance obligations through secure technology, privacy-focused design, and operational safeguards.
Our platform includes security features such as:
Encryption of data in transit using industry-standard TLS protocols
Encryption of sensitive data at rest
Role-based access controls
Authentication and secure account management
Audit logging and system monitoring
Secure cloud infrastructure
Ongoing security updates and vulnerability management
Principle of least privilege for internal access to customer data
Business Associate Agreements (BAAs)
Because Annie may process Protected Health Information on behalf of covered entities, we offer Business Associate Agreements (BAAs) to eligible customers.
Our BAA clearly defines our responsibilities regarding the protection, handling, and safeguarding of PHI.
If your practice requires a signed BAA before implementation, our team can provide one during onboarding.
Secure AI Built for Healthcare
Unlike general-purpose AI tools, Annie is purpose-built for dental practices.
Our AI is designed to:
Handle patient conversations securely
Protect sensitive information throughout workflows
Minimize unnecessary exposure of PHI
Support healthcare-specific communication needs
Security and privacy considerations are incorporated into product development as new features are released.
Employee Security Practices
Technology is only one part of protecting patient information.
Our team follows internal security practices designed to help protect customer data, including:
Security and privacy training
Access controls based on job responsibilities
Authentication requirements
Confidentiality obligations
Incident response procedures
Ongoing security awareness
Infrastructure Security
Annie utilizes modern cloud infrastructure designed for reliability and security.
Our infrastructure includes safeguards such as:
Network security controls
Continuous monitoring
Regular backups
High availability architecture
Disaster recovery planning
Automated security updates where appropriate
Your Role in HIPAA Compliance
HIPAA compliance is a shared responsibility.
While Annie provides secure technology and operational safeguards, healthcare organizations remain responsible for:
Proper user access management
Employee HIPAA training
Internal privacy policies
Appropriate use of patient information
Compliance with applicable federal and state regulations
We encourage every practice to review its own compliance policies regularly.
Frequently Asked Questions
Is Annie HIPAA compliant?
Annie is designed to support HIPAA compliance through secure infrastructure, encryption, access controls, and privacy-focused operational practices. Healthcare organizations remain responsible for their own compliance programs and internal policies.
Does Annie sign a Business Associate Agreement (BAA)?
Yes. Annie offers Business Associate Agreements (BAAs) for eligible customers.
Is patient data encrypted?
Yes. Data is encrypted both in transit and at rest using industry-standard encryption technologies.
Who can access our data?
Access is limited to authorized personnel with a legitimate business need and is governed by internal access controls and security policies.
Does Annie use patient data to train AI models?
Patient data is handled according to our contractual commitments, privacy policies, and applicable laws. We do not use customer PHI to train general-purpose AI models without appropriate authorization or contractual permission.
(Only keep this statement if it accurately reflects Annie's AI/data practices.)
How is customer data protected?
Annie employs multiple layers of security, including encryption, authentication, access controls, monitoring, and secure cloud infrastructure designed to protect customer information.
What happens if there is a security incident?
Annie maintains incident response procedures designed to investigate, contain, and address security events. Customers are notified as required by applicable agreements and regulations.
Questions About Security?
Our team is happy to answer questions about our security practices, privacy protections, or HIPAA-related documentation.