HIPAA Compliance and BAA
OzyOps is built for healthcare practices and takes HIPAA compliance seriously. This page explains how we protect patient data and what your responsibilities are.
OzyOps as a Business Associate
Under HIPAA, OzyOps is a Business Associate of your practice. This means we handle Protected Health Information (PHI) on your behalf and are legally obligated to protect it.
Business Associate Agreement (BAA)
Every healthcare customer signs a BAA during onboarding. The BAA covers:
- What PHI we receive and how we use it
- Our security obligations
- Breach notification procedures
- Data retention and destruction timelines
- Your rights regarding your patients' data
To view your signed BAA: Go to Settings > Profile in your dashboard.
PHI Categories We Collect
During AI-handled calls, the following patient information may be collected:
| Category | Examples |
|---|---|
| Identifiers | Name, phone number, email address, date of birth |
| Health information | Reason for visit, symptoms described, medications (for refill requests) |
| Scheduling data | Appointment dates, provider assignments, procedure types |
| Insurance | Carrier name, member ID (if provided during the call) |
| Payment | Payment method type (cash, card, insurance -- no card numbers are collected) |
| Communication records | Call recordings, transcripts, SMS messages |
The AI does not ask for or store credit card numbers, Social Security numbers, or bank account details during calls.
Data Encryption
All PHI is protected with multiple layers of encryption:
- In transit: TLS 1.2+ encryption for all data moving between systems.
- At rest: AES-256 encryption for stored data, including call recordings, transcripts, and patient records.
- EMR credentials: AES-256-GCM encryption for stored EMR API keys and OAuth tokens.
Multi-Factor Authentication (MFA)
MFA is mandatory for all healthcare accounts. Every team member must set up MFA before accessing the dashboard.
This adds a second layer of security beyond your password. Even if your password is compromised, an attacker cannot access your account without the MFA code from your phone.
See the MFA Setup Guide for instructions.
Subprocessors
OzyOps uses the subprocessors below. The BAA column states the actual status of each, including the vendors where no BAA is in place.
| Subprocessor | Purpose | PHI involved | BAA |
|---|---|---|---|
| Retell AI | Voice AI platform (handles all calls) | Yes | Signed 12/15/2025 |
| Neon | PostgreSQL database holding healthcare records | Yes | Signed 3/29/2026 |
| NexHealth | Practice-management integration (only for practices using one, e.g. Dentrix) | Yes | In place, incorporated by reference through their API License Agreement |
| Twilio | SMS delivery and phone numbers | Yes | No BAA. Staff SMS carrying a patient name were sent Jul 20 to 31 2026, so the earlier "no PHI" basis is under re-examination |
| Supabase | Authentication, customer records, outbound SMS log | Yes, in the outbound SMS log | No BAA |
| Sentry | Error tracking | Not intended. Identifiers are redacted before transmission, but that redaction reduces exposure rather than preventing it | No BAA |
| Netlify | Hosting and serverless functions | Transient processing only | No BAA. A data processing agreement is executed |
| Resend | Transactional email | No. Reminder emails carry counts only | Not applicable |
| Stripe | Billing | No | Not applicable |
Where a BAA is in place, that vendor is contractually bound to protect PHI under HIPAA. Where none is in place, the vendor has no contractual duty to notify OzyOps of a security incident, so our own monitoring is the detection path rather than a backstop.
Data Retention
OzyOps retains healthcare data according to the following schedule. Where state law requires longer, the longer period applies.
| Data Type | Retention | Held in |
|---|---|---|
| Call transcripts | 6 years from your last date of service | Neon |
| Patient contact information and call records | 6 years from your last date of service | Neon |
| Audit logs | 6 years from the date of the log entry | Neon and Supabase |
| Call recordings (audio) | Held under Retell's retention policy. OzyOps does not store recording URLs | Retell AI |
| Outbound SMS log | Retained. The specific period is under review as of August 2026 | Supabase |
| Non-healthcare call logs (trades, law) | 3 years from the date of the call | Supabase |
| Business records (billing, contracts) | 7 years | Stripe and version control |
The 6-year periods follow 45 CFR 164.530(j). Some states require longer: California and Texas set 7 years from the last date of service, Florida 7 years from last patient contact, and for minors California runs to age 19 and Florida to age 25. Before any deletion we check the applicable state law and apply whichever period is longer.
When you cancel your account, call data stays accessible in your dashboard for 30 days. After that it is retained under the schedule above rather than deleted, and returned or destroyed on request under your BAA. Request a data export before cancellation if you want your own copy.
Your Responsibilities
As the healthcare practice (the Covered Entity), you are responsible for:
- Signing the BAA -- Completed during onboarding.
- Enforcing MFA -- All team members must set up MFA. OzyOps requires this automatically.
- Managing team access -- Remove team members promptly when they leave your practice.
- Patient consent -- Obtaining any required patient consent for AI-handled calls and SMS communication.
- Breach reporting -- Notifying OzyOps if you suspect unauthorized access to your account.
- Minimum necessary -- Only sharing the minimum necessary PHI in your AI agent's special instructions.
Breach Notification
If OzyOps discovers or suspects a security breach involving PHI, your BAA commits us to the following. These are contractual commitments, and both are shorter than the 60 days HIPAA itself allows.
- Within 24 hours of discovery, we notify you of the suspected or confirmed breach, by phone and then in writing.
- Within 7 business days, or sooner where your own BAA sets a shorter period, we give you a written report: when we discovered it, when it happened, which PHI was involved, which identifiers were exposed, how many individuals are affected, and what we have done and will do to limit the harm.
- We preserve evidence, investigate, and give you everything you need for your own breach risk assessment.
- We support your obligation to notify affected patients and HHS, where that applies.
If you discover or suspect a breach (unauthorized access to your account, lost device with dashboard access, etc.), contact us immediately at security@ozyops.com.
Common Questions
Is OzyOps HIPAA certified? There is no official "HIPAA certification." HIPAA compliance is demonstrated through policies, procedures, technical safeguards, and BAAs. OzyOps implements administrative, physical, and technical safeguards required by the HIPAA Security Rule.
Can I use OzyOps without signing a BAA? For healthcare practices that handle PHI, a BAA is required. Non-healthcare customers (trades, law) do not need a BAA.
What happens if a team member's phone is lost or stolen? The team member should notify the account Owner immediately. The Owner should remove the team member from Settings > Team and contact support@ozyops.com. If MFA was set up on the lost device, see the Account Recovery guide.
Does OzyOps conduct security audits? Yes. We perform regular security assessments and maintain security policies aligned with HIPAA requirements. Contact security@ozyops.com for details.
Can I request a copy of OzyOps security policies? Yes. Contact support@ozyops.com with the subject "Security Documentation Request."