Security & HIPAA

Patient data is the whole business. We treat it that way.

Dentaris automates revenue cycle work that runs on protected health information, so security is not a checklist for us — it is the operating constraint everything else is built around.

Encrypted everywhere

All traffic runs over TLS, and data is encrypted at rest with AES-256 on our cloud infrastructure. There is no unencrypted path for patient data, in motion or on disk.

Clinic-scoped access

Every record is bound to a clinic, and every query is filtered by it. Staff at one location can never see another location’s patients, and Dentaris workforce access follows the minimum-necessary standard.

You stay in control

Every workflow can run in approve-first mode: the AI drafts the claim fix, appeal, or patient outreach, and nothing is sent until your team clicks approve. Autonomy is a setting, not a requirement.

Everything is logged

Every automated action — claims submitted, appeals filed, texts sent, payments posted — is recorded with what happened, when, and on whose approval. The audit trail is part of the product, not an add-on.

PHI never trains models

Patient data is used to do the work you hired Dentaris for, nothing else. It is never sold, never shared beyond the subprocessors below, and never used to train AI models.

The demo is PHI-free

The public demo at dentaris.io/demo runs entirely on fictional sample data. No real patient, practice, or payer data is involved until a pilot begins under a signed agreement.

Subprocessors

Dentaris uses a deliberately short list of infrastructure vendors. Where PHI is stored or processed, a BAA is in place for production engagements.

  • SupabaseDatabase, authentication, and row-level access control (US region)
  • NetlifyApplication hosting and content delivery
  • Open Dental APIPractice-management system integration during pilots

Common questions

Will Dentaris sign a BAA?

Yes. For production pilots handling PHI, Dentaris signs a Business Associate Agreement with your practice, and we maintain BAAs with the infrastructure subprocessors that store or process PHI on our behalf.

Where does our data live?

In US cloud regions, encrypted at rest. Data is retained for the duration of your agreement and deleted on request when the engagement ends.

Who at Dentaris can see our data?

Access is limited to the engineers who operate your pilot, under the minimum-necessary standard, with logged access. Nobody browses patient data casually — support access happens with your knowledge.

What happens if something goes wrong?

We commit to breach-notification timelines in the BAA and will notify you promptly of any incident affecting your data, with a full account of scope and remediation.

Want the details?

We'll walk your team through the architecture and answer anything here in more depth.

Request a security review