Frontis signs a HIPAA Business Associate Agreement with every dental practice before going live. Here is what it covers.
Under HIPAA, when a dental practice (a “Covered Entity”) shares Protected Health Information with a third-party vendor (a “Business Associate”), a signed Business Associate Agreement is legally required before any PHI is shared.
When a patient calls your practice and Frontis answers, that call may involve PHI — the patient’s name, date of birth, symptoms, insurance details. That makes Frontis your Business Associate, and a BAA must be in place before the first call.
This is non-negotiable under HIPAA. We will not go live with any practice without a signed BAA.
| Safeguard | Implementation |
|---|---|
| Encryption at rest | AES-256 on all stored recordings and transcripts (AWS S3) |
| Encryption in transit | TLS 1.3 on all data transmission |
| Access controls | Role-based access, audit logging on all PHI access |
| Data retention | 90 days default; practice-controlled deletion available |
| Breach detection | AWS CloudWatch monitoring with automated alerting |
| BAA with subprocessors | Signed with Vapi, Twilio, AWS, Resend |
Your BAA is sent automatically as part of onboarding. If you need it ahead of time, contact us at hello@frontis.ai and we will send the DocuSign link within one business day.