Security

Built to be safe on a clinical phone line.

This page is written for the person who actually runs the practice — not for a legal team. Here's what we protect, how, and what our AI will never do.

"Our AI never gives medical advice, never discusses results, and does not clinically assess symptoms — it follows the escalation rules your practice approves, and calls matching your emergency rules are transferred immediately."

The clinical guardrail is not a setting you can accidentally turn off. It's how the system is built.

  • HIPAA configuration

    Call data lives in a HIPAA-configured environment with access logging, least-privilege permissions and vendor controls reviewed before anything touches your patients' information.

  • Business Associate Agreements

    A signed Business Associate Agreement is included with every CliniRelay plan at no additional charge. You get a plain-language summary of what we handle, what we store, and for how long — not a 40-page PDF you have to decode. Our BAA is a standard agreement aligned with our infrastructure providers' terms. Custom BAA language is available on Enterprise plans.

  • Encryption

    Everything is encrypted in transit and at rest. Transcripts, recordings and summaries are protected the same way, and staff access is scoped to your practice only.

  • Call recording controls

    You decide whether calls are recorded, whether transcripts are kept, and how long we retain them. Turn recording off entirely and you still get written summaries.

  • Who can see what

    Role-based access means your front desk sees what it needs and your administrators see everything. Every export and every login is logged.

Want the BAA and controls reviewed before you commit?

We'll walk your practice manager and your compliance contact through it before you sign anything.

Start Free Month