Skip to content
optniai

Trust

HIPAA, TCPA and the carrier rules — handled before you go live

Patient calls and texts are regulated three different ways in the US. Here is exactly how each one is covered, in plain language.

In short

optni.ai operates as a HIPAA Business Associate and executes a Business Associate Agreement with every customer on every plan. Protected health information is encrypted with TLS 1.3 in transit and AES-256 at rest, protected by role-based access control, and logged for six years. Text messaging is registered under A2P 10DLC with express written consent captured at the point of collection and STOP handling built in, and call-recording consent notices are delivered automatically in two-party-consent states.

Safeguards

What is actually in place

Business Associate Agreement

Executed with every customer on every plan, including Starter. Compliance is not an upsell — a solo practice handles the same PHI as a ten-location group.

Encryption in transit

TLS 1.3 on every connection carrying protected health information, including call audio, transcripts and message content.

Encryption at rest

AES-256 on all stored recordings, transcripts, messages and patient records.

Role-based access control

Staff see only what their role requires. Access grants are reviewed and revocable, and every access event is recorded.

Audit logging

Six-year retention on access and disclosure events, matching the HIPAA documentation retention requirement.

Subprocessor BAAs

Every vendor in the path of PHI — telephony, storage, model inference — operates under its own executed BAA. The list is available on request.

Minimum necessary by default

Max keeps clinical detail out of SMS bodies unless the patient has consented. Messages default to the least information that still does the job.

Breach notification

Documented procedures aligned to the HIPAA Breach Notification Rule, with defined timelines and a named responsible party.

Boundaries

What Ava and Max will never do

  • Give medical, dental or veterinary advice
  • Perform clinical triage or assess symptoms
  • Claim to be a human being
  • Diagnose, interpret results or discuss treatment suitability
  • Approve a prescription or refill without staff authorization
  • Share PHI with anyone outside your configured staff

Compliance questions

Asked and answered

optni.ai is built to operate as a Business Associate under HIPAA and executes a Business Associate Agreement with every customer. It is worth being precise about the language: no software product is 'HIPAA certified', because no such certification exists. What matters is whether the vendor signs a BAA and meets the Security Rule's technical safeguards — encryption in transit and at rest, access controls, audit logging and breach procedures. optni.ai does.

Standard SMS is not inherently secure, which is why the safeguards sit at the platform level and why message content is minimised by default. Texting patients is permitted under HIPAA where the patient has been warned of the risks and has agreed, the platform operates under a BAA, and the content is limited to the minimum necessary. optni.ai captures that consent and keeps clinical detail out of message bodies unless the patient opts in.

A2P 10DLC is the registration US carriers require for application-to-person text messaging. Since February 2025 carriers block unregistered traffic outright, and penalties can reach $10,000 per violation. optni.ai completes brand and campaign registration on your behalf during onboarding at no extra cost — you do not file it yourself.

Several US states require all parties to consent to a call being recorded. Ava delivers a spoken consent notice at the start of the call wherever your practice operates in a two-party-consent state, and the configuration is set during onboarding based on your location.

They are encrypted at rest, access-controlled, and retained according to the retention period you configure. You can export or delete your data at any time, and deletion propagates to subprocessors.

Not yet. A SOC 2 Type II audit is on the roadmap and we will publish the report when it completes. We would rather say that plainly than imply a certification we do not hold.

Want the BAA before you talk to us?

Reasonable. Ask and we will send the agreement and the subprocessor list for your counsel to review before any call is placed.