Skip to main content

HIPAA Compliance and BAA

OzyOps is built for healthcare practices and takes HIPAA compliance seriously. This page explains how we protect patient data and what your responsibilities are.

OzyOps as a Business Associate

Under HIPAA, OzyOps is a Business Associate of your practice. This means we handle Protected Health Information (PHI) on your behalf and are legally obligated to protect it.

Business Associate Agreement (BAA)

Every healthcare customer signs a BAA during onboarding. The BAA covers:

  • What PHI we receive and how we use it
  • Our security obligations
  • Breach notification procedures
  • Data retention and destruction timelines
  • Your rights regarding your patients' data

To view your signed BAA: Go to Settings > Profile in your dashboard.

PHI Categories We Collect

During AI-handled calls, the following patient information may be collected:

CategoryExamples
IdentifiersName, phone number, email address, date of birth
Health informationReason for visit, symptoms described, medications (for refill requests)
Scheduling dataAppointment dates, provider assignments, procedure types
InsuranceCarrier name, member ID (if provided during the call)
PaymentPayment method type (cash, card, insurance -- no card numbers are collected)
Communication recordsCall recordings, transcripts, SMS messages
The AI never collects sensitive financial data

The AI does not ask for or store credit card numbers, Social Security numbers, or bank account details during calls.

Data Encryption

All PHI is protected with multiple layers of encryption:

  • In transit: TLS 1.2+ encryption for all data moving between systems.
  • At rest: AES-256 encryption for stored data, including call recordings, transcripts, and patient records.
  • EMR credentials: AES-256-GCM encryption for stored EMR API keys and OAuth tokens.

Multi-Factor Authentication (MFA)

MFA is mandatory for all healthcare accounts. Every team member must set up MFA before accessing the dashboard.

This adds a second layer of security beyond your password. Even if your password is compromised, an attacker cannot access your account without the MFA code from your phone.

See the MFA Setup Guide for instructions.

Subprocessors

OzyOps uses the subprocessors below. The BAA column states the actual status of each, including the vendors where no BAA is in place.

SubprocessorPurposePHI involvedBAA
Retell AIVoice AI platform (handles all calls)YesSigned 12/15/2025
NeonPostgreSQL database holding healthcare recordsYesSigned 3/29/2026
NexHealthPractice-management integration (only for practices using one, e.g. Dentrix)YesIn place, incorporated by reference through their API License Agreement
TwilioSMS delivery and phone numbersYesNo BAA. Staff SMS carrying a patient name were sent Jul 20 to 31 2026, so the earlier "no PHI" basis is under re-examination
SupabaseAuthentication, customer records, outbound SMS logYes, in the outbound SMS logNo BAA
SentryError trackingNot intended. Identifiers are redacted before transmission, but that redaction reduces exposure rather than preventing itNo BAA
NetlifyHosting and serverless functionsTransient processing onlyNo BAA. A data processing agreement is executed
ResendTransactional emailNo. Reminder emails carry counts onlyNot applicable
StripeBillingNoNot applicable

Where a BAA is in place, that vendor is contractually bound to protect PHI under HIPAA. Where none is in place, the vendor has no contractual duty to notify OzyOps of a security incident, so our own monitoring is the detection path rather than a backstop.

Data Retention

OzyOps retains healthcare data according to the following schedule. Where state law requires longer, the longer period applies.

Data TypeRetentionHeld in
Call transcripts6 years from your last date of serviceNeon
Patient contact information and call records6 years from your last date of serviceNeon
Audit logs6 years from the date of the log entryNeon and Supabase
Call recordings (audio)Held under Retell's retention policy. OzyOps does not store recording URLsRetell AI
Outbound SMS logRetained. The specific period is under review as of August 2026Supabase
Non-healthcare call logs (trades, law)3 years from the date of the callSupabase
Business records (billing, contracts)7 yearsStripe and version control

The 6-year periods follow 45 CFR 164.530(j). Some states require longer: California and Texas set 7 years from the last date of service, Florida 7 years from last patient contact, and for minors California runs to age 19 and Florida to age 25. Before any deletion we check the applicable state law and apply whichever period is longer.

Account cancellation

When you cancel your account, call data stays accessible in your dashboard for 30 days. After that it is retained under the schedule above rather than deleted, and returned or destroyed on request under your BAA. Request a data export before cancellation if you want your own copy.

Your Responsibilities

As the healthcare practice (the Covered Entity), you are responsible for:

  1. Signing the BAA -- Completed during onboarding.
  2. Enforcing MFA -- All team members must set up MFA. OzyOps requires this automatically.
  3. Managing team access -- Remove team members promptly when they leave your practice.
  4. Patient consent -- Obtaining any required patient consent for AI-handled calls and SMS communication.
  5. Breach reporting -- Notifying OzyOps if you suspect unauthorized access to your account.
  6. Minimum necessary -- Only sharing the minimum necessary PHI in your AI agent's special instructions.

Breach Notification

If OzyOps discovers or suspects a security breach involving PHI, your BAA commits us to the following. These are contractual commitments, and both are shorter than the 60 days HIPAA itself allows.

  1. Within 24 hours of discovery, we notify you of the suspected or confirmed breach, by phone and then in writing.
  2. Within 7 business days, or sooner where your own BAA sets a shorter period, we give you a written report: when we discovered it, when it happened, which PHI was involved, which identifiers were exposed, how many individuals are affected, and what we have done and will do to limit the harm.
  3. We preserve evidence, investigate, and give you everything you need for your own breach risk assessment.
  4. We support your obligation to notify affected patients and HHS, where that applies.

If you discover or suspect a breach (unauthorized access to your account, lost device with dashboard access, etc.), contact us immediately at security@ozyops.com.

Common Questions

Is OzyOps HIPAA certified? There is no official "HIPAA certification." HIPAA compliance is demonstrated through policies, procedures, technical safeguards, and BAAs. OzyOps implements administrative, physical, and technical safeguards required by the HIPAA Security Rule.

Can I use OzyOps without signing a BAA? For healthcare practices that handle PHI, a BAA is required. Non-healthcare customers (trades, law) do not need a BAA.

What happens if a team member's phone is lost or stolen? The team member should notify the account Owner immediately. The Owner should remove the team member from Settings > Team and contact support@ozyops.com. If MFA was set up on the lost device, see the Account Recovery guide.

Does OzyOps conduct security audits? Yes. We perform regular security assessments and maintain security policies aligned with HIPAA requirements. Contact security@ozyops.com for details.

Can I request a copy of OzyOps security policies? Yes. Contact support@ozyops.com with the subject "Security Documentation Request."