AES-256 at rest
Patient records, recordings, and document blobs encrypted at rest in AWS S3 with KMS-managed customer keys.
Patient data is sacred. We treat it that way. Here is the architecture that protects it, the controls that govern it, and the certifications we hold (and are pursuing).
Patient records, recordings, and document blobs encrypted at rest in AWS S3 with KMS-managed customer keys.
Modern cipher suites only. HSTS preloaded. Certificate pinning on mobile.
AWS Comprehend Medical strips identifiers before any LLM call. Redaction is logged and audited.
Patient data is not used to train third-party AI models. We configure supported AI services with no-retention or no-training settings where available, and PHI is only processed for the customer's authorized workflow.
Patient · Front-desk · Dentist · Practice Manager · Founder. Least privilege, enforced at the API layer.
Two pools (practice + patient). MFA required for all staff. Session timeouts configurable per role.
Every PHI read, write, export, or share creates an immutable audit record. 7-year retention.
No AI output enters the official record without a clinician's electronic signature.
AWS, Deepgram, Telnyx, Stripe — all under signed BAAs where they touch PHI.
Bedrock + Deepgram traffic stays inside our VPC. No public-internet model calls.
15-minute SLA on PHI incidents. Breach notification protocol aligned with HIPAA §164.404.
Independent third-party pen-tests every 90 days. Summary letters available under NDA.
Trace a single visit through every layer. Every step is encrypted, audited, and minimal.
Microphone in the operatory. Audio buffered locally, never persisted to disk.
Chunks streamed to our VPC over mutual-auth TLS. Session token expires in 15 min.
Comprehend Medical strips PII before any LLM. Original audio destroyed on close.
Bedrock generates SOAP. No retention. No training. No third party.
Dentist reviews & signs. Note encrypted in S3 + written to your PMS via the secure connector.
| Provider | Purpose | Region | BAA |
|---|---|---|---|
| AWS · S3, SES, SNS, SQS, Cognito, KMS | Infrastructure, storage, identity | us-east-1, us-west-2 | SIGNED |
| AWS Bedrock | LLM inference for SOAP + summaries | us-east-1 | SIGNED |
| AWS Comprehend Medical | PHI redaction pipeline | us-east-1 | SIGNED |
| Deepgram | Medical-grade transcription | US | SIGNED |
| Telnyx | Voice agent telephony | US | SIGNED |
| Stripe | Subscription billing (no PHI) | US | N/A |
| PostgreSQL on AWS RDS | Operational database (encrypted) | us-east-1 | SIGNED |
Standard Business Associate Agreement (signable PDF).
What we collect, what we don't, what you control.
Standard SaaS terms. Month-to-month. Plain English.
For practices with extra compliance requirements.
One-pager for your IT review. Controls + architecture.
Most recent third-party pen-test summary (NDA-gated).
Live list of every vendor in the data path.
Question we didn’t answer? Direct line.
A real security engineer reads every email at security@practicepilotai.com. Pen-test letters are available under NDA.