HIPAA Compliance
How we protect Protected Health Information across every AI workflow on the Solara platform.
Compliance Overview
Protecting Protected Health Information (PHI) is a fundamental part of the Solara platform. We have built our architecture from the ground up to comply with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
Business Associate Agreements
As a technology provider handling PHI on behalf of covered entities (dental practices), Solara acts as a Business Associate. We require all dental practices using our platform to sign our standard Business Associate Agreement (BAA) prior to onboarding. This BAA contractually guarantees our adherence to the HIPAA Security and Privacy Rules.
Handling of PHI
When our AI Voice Bot speaks with patients, or when our automated intake system processes forms, we strictly control how PHI is accessed:
- Minimum Necessary: Our AI models only process the data required to complete the specific task (for example, verifying a specific insurance policy).
- Anonymization: Where possible, conversational data used for training aggregate AI models is scrubbed of identifying PHI.
- Data Residency: All data is stored within certified cloud regions physically located in the United States.
Security Measures
Solara implements strict physical, technical, and administrative safeguards to ensure the confidentiality and integrity of electronic PHI (ePHI):
- Encryption: All ePHI is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
- Access Controls: Our staff operates on a strict zero-trust model. No engineer can access production databases without explicit, temporary clearance for troubleshooting.
- Vulnerability Scanning: We conduct continuous vulnerability scanning and annual third-party penetration testing.
Auditing & Logging
The Solara platform maintains comprehensive, immutable audit logs of all system activity. Whenever PHI is accessed, modified, or deleted — whether by a human operator or an AI agent — the action is logged with precise timestamps and identity attribution to support compliance audits.
Questions about this policy?
Our compliance team is happy to help clarify anything on this page.