HIPAA Compliance
Our Approach to Healthcare Clients
We support healthcare providers with HIPAA-conscious workflows, including intake, triage, appointment scheduling, and secure message handling.
Business Associate Agreements (BAA)
We offer BAAs for eligible plans and use cases. Any Business Associate Agreement is entered into with The Phoenix Ascension Group, Inc., a Florida corporation operating as Gold Coast AI, as the named legal entity. Please contact Isaias@InteliaRD.com to request a BAA.
Data Security Measures
- Encryption in transit and at rest where applicable
- Access controls, audit logs, and least-privilege practices
- Vendor risk management and secure integrations
Call Recording Consent
Call recordings are only enabled with proper consent and in compliance with all-party/one-party consent laws, as applicable to the jurisdiction.
Data Security & Compliance FAQ
We build on a self-hosted stack: n8n and a Qdrant vector database run on our own VPS, not a third-party managed cloud pipeline. That gives healthcare clients more control over where transcripts and records live and who can access them, which matters for HIPAA-sensitive work.
Our agents are retrieval-grounded (RAG): they answer only from approved, retrieved sources rather than improvising, and consequential actions route to a human. Access is scoped to least privilege, so the agent only touches the data a task actually requires.
Yes, for eligible plans and use cases. If your project will touch protected health information, we put a BAA in place before any build and design the architecture to keep that data controlled. Email Isaias@InteliaRD.com to request one.
You do. Because the stack is self-hosted on infrastructure you can control, there is no vendor lock-in on your data, and access can be revoked or migrated at the end of an engagement.