HIPAA Compliance
Our Approach to Healthcare Clients
We support healthcare providers with HIPAA-conscious workflows, including intake, triage, appointment scheduling, and secure message handling.
Business Associate Agreements (BAA)
We offer BAAs for eligible plans and use cases. Please contact Isaias@InteliaRD.com to request a BAA.
Data Security Measures
- Encryption in transit and at rest where applicable
- Access controls, audit logs, and least-privilege practices
- Vendor risk management and secure integrations
Call Recording Consent
Call recordings are only enabled with proper consent and in compliance with all-party/one-party consent laws, as applicable to the jurisdiction.
Data Security & Compliance FAQ
We build on a self-hosted stack: n8n and a Qdrant vector database run on our own VPS, not a third-party managed cloud pipeline. That gives healthcare clients more control over where transcripts and records live and who can access them, which matters for HIPAA-sensitive work.
Our agents are retrieval-grounded (RAG): they answer only from approved, retrieved sources rather than improvising, and consequential actions route to a human. Access is scoped to least privilege, so the agent only touches the data a task actually requires.
Yes, for eligible plans and use cases. If your project will touch protected health information, we put a BAA in place before any build and design the architecture to keep that data controlled. Email Isaias@InteliaRD.com to request one.
You do. Because the stack is self-hosted on infrastructure you can control, there is no vendor lock-in on your data, and access can be revoked or migrated at the end of an engagement.