HIPAA Compliance Notice
Last updated: April 16, 2026
ClarioScope AI is designed from the ground up with healthcare privacy in mind. This notice explains what data we handle, when your practice needs a Business Associate Agreement (BAA), and how our compliance infrastructure protects you.
Our Compliance Infrastructure
Data Encryption
AES-256 encryption for all data at rest. TLS 1.3 for all data in transit. No unencrypted storage of any client or patient data anywhere in our infrastructure.
BAA Execution
A Business Associate Agreement is executed with every client using services that handle PHI. We countersign BAAs within two business days and maintain executed copies for the required 6-year retention period.
Access Controls
Role-based access control (RBAC) ensures only authorized personnel access PHI. Multi-factor authentication (MFA) is required for all privileged accounts. Session timeouts enforce HIPAA workstation security.
Breach Notification
Documented incident response procedures. In the event of a confirmed breach of unsecured PHI, affected covered entities are notified within 60 days of discovery as required by HITECH, with full incident reports.
Workforce Training
All ClarioScope AI employees complete mandatory HIPAA Privacy and Security training upon hire and annually thereafter. Completion records are maintained and available for audit upon request.
Security Audits
Annual formal HIPAA risk analyses per 45 C.F.R. § 164.308(a)(1). Annual third-party penetration testing. Our infrastructure is hosted on AWS with SOC 2 Type II certification.
1. What ClarioScope AI Does and Does Not Do With Health Information
ClarioScope AI provides two categories of services with very different data handling profiles. Understanding which category applies to your practice determines whether you need to execute a BAA.
Standard Services
No PHI involved — BAA not required
- Diagnostic scan of your public-facing web presence
- SEO keyword research and content strategy
- Google Business Profile optimization
- Social media content creation and scheduling
- Anonymous website analytics and performance reporting
- Paid advertising (Google Ads, Meta) without patient identifiers
Enhanced Services
PHI may be involved — BAA REQUIRED
- AI Receptionist — processes inbound call audio and may capture patient identifiers
- Appointment scheduling integrations where patient names or dates of service flow through our platform
- Direct patient communication workflows linking appointment data to identifiable individuals
- Any custom integration where PHI from your EHR or PMS passes through ClarioScope AI systems
2. AI Receptionist and HIPAA
The ClarioScope AI Receptionist is a VAPI-powered voice AI that handles inbound calls on behalf of your practice — scheduling appointments, answering FAQs, and routing urgent calls to your staff. Because this service may capture and process information about identifiable patients, it constitutes a HIPAA Business Associate function.
- Call recording encryption: All call recordings are encrypted in transit using TLS 1.3 and stored at rest with AES-256 encryption on HIPAA-compliant AWS infrastructure. Recordings are retained only for the period specified in your service agreement (default: 90 days) and are accessible only to authorized personnel.
- AI session data handling: Transcriptions generated by the AI Receptionist are treated as ePHI where they contain identifiable patient information. They are stored in your practice's portal (accessible only to authorized staff) and are not used to train general AI models. Session logs are subject to the same 90-day or BAA-specified retention schedule.
- BAA requirement: A signed BAA between your practice and ClarioScope AI is required before the AI Receptionist can be activated. ClarioScope AI also maintains a BAA with VAPI as a HIPAA subcontractor. The AI Receptionist will not be enabled on any account that has not completed BAA execution.
- Script and call flow compliance: All AI Receptionist scripts are reviewed by your authorized representative before deployment. Scripts are designed to avoid unlicensed medical advice and to comply with applicable state telehealth and call recording consent laws (including two-party consent states).
3. Review and Reputation Management
ClarioScope AI's reputation management module monitors and helps you respond to patient reviews on Google, Healthgrades, Yelp, and other public platforms. This service is designed to operate without requiring access to PHI in most standard configurations.
- Public review handling: Reviews posted by patients on public platforms are by definition not confidential under HIPAA. However, our response drafting protocol instructs you never to confirm or deny that the reviewer is a patient of your practice, in compliance with OCR guidance on HIPAA and public review responses.
- No PHI in review requests: Review generation campaigns (automated requests to patients asking them to leave reviews) are conducted using only names and contact information provided through HIPAA-compliant channels. Where review requests are sent using patient appointment data, this requires a BAA and falls under Enhanced Services.
- Response drafting compliance: AI-drafted responses to negative or sensitive reviews are reviewed by you before posting. Draft responses are designed to: avoid confirming the patient relationship, avoid disclosing any clinical information, acknowledge the feedback professionally, and invite the reviewer to contact the practice directly to resolve concerns.
4. Marketing Content Compliance
Healthcare marketing is subject to FTC regulations, state medical board rules, and HIPAA's marketing provisions. ClarioScope AI builds compliance checkpoints into every campaign workflow.
- FTC endorsement rules: All patient testimonials and endorsements must represent the genuine experience of the patient. Material connections between the practice and the reviewer (e.g., compensation, free services) must be disclosed. ClarioScope AI will not publish or distribute testimonials that violate 16 C.F.R. Part 255 (FTC Endorsement Guides).
- Testimonial substantiation requirements: Testimonials may only claim outcomes that are typical for patients receiving the relevant treatment or service. Atypical results must be accompanied by a clear, conspicuous disclaimer ("Individual results may vary. Consult with a qualified provider to determine if this treatment is right for you.").
- Outcome claim requirements: Specific outcome claims (e.g., success rates, patient satisfaction scores) must be documented with verifiable evidence. We will request the supporting data before publishing any quantitative outcome claims in your marketing materials.
- Before/after photo consent: Before-and-after photographs used in any marketing context require documented patient consent specifying the approved uses (digital advertising, website, social media, print, etc.). You are responsible for maintaining consent records. ClarioScope AI will not publish before-and-after photography without written confirmation from your authorized representative that consent has been obtained for the specific intended use.
5. Frequently Asked Questions
HIPAA Contacts
HIPAA Privacy Officer
For privacy questions, individual rights requests, HIPAA compliance inquiries, and reporting a potential privacy or security incident:
privacy@clarioscope.aiWe respond to all HIPAA inquiries within 2 business days.
BAA Requests
To request a Business Associate Agreement for AI Receptionist or Enhanced Services activation:
legal@clarioscope.aiBAA countersignature SLA: 2 business days from receipt of your executed copy.
ClarioScope AI, Inc. · 1 SE 3rd Avenue, Suite 2000, Miami, FL 33131 · View Full BAA · Privacy Policy
