Compliance & Security
HIPAA, BAA, call-recording laws, data retention, and security practices.
- HIPAA & FrontDesk — overviewFrontDesk is built to be HIPAA-eligible for healthcare practices. Call audio, transcripts, patient records, and AI summaries all live in HIPAA-eligible infrastructure (AWS), encrypted at rest and in transit. We sign a Business Associate Agreement (BAA) with practices on qualifying plans before any real patient data is processed. This article is the overview — see "Sign your BAA" for the how-to.2 min
- Verify caller identity before sharing recordsWhen "Verify identity before sharing records" is on, your AI confirms the caller's identity before it discusses anything personal — appointments, balances, or treatment details. General help like your hours, directions, or booking a new appointment never requires verification. If the caller can't be confirmed, the AI won't share personal details and instead offers to take a message or have a team member follow up. It's an optional, per-practice safeguard you can turn on when you want an extra layer of privacy protection.2 min
- Sign your Business Associate Agreement (BAA)HIPAA requires a signed Business Associate Agreement between you (covered entity) and us (business associate) before we can handle PHI on your behalf. Sign electronically from Settings → Organization → HIPAA Compliance. Takes 2 minutes; valid for the life of your account.2 min
- Understand call recording consent13 US states require all parties on a call to consent to recording. FrontDesk auto-detects when a caller is in a two-party state and plays a consent prompt at the start of the call. Decline = call continues without recording. Accept = full audio recording.2 min
- Review your audit trailThe Audit Trail logs every time someone views, updates, or exports patient information in FrontDesk — who did it, when, from what IP, and the outcome. Filter by action type (views, updates, exports), search by name or resource, and choose a date range from the last 7 days to all time. You can export the log itself as a CSV, and owners and admins can request a full account-data export. HIPAA requires this kind of access logging, and FrontDesk keeps it automatically.2 min
- Data retention and deletionDefaults differ by data type and whether you're a healthcare org — call recordings 7 years (healthcare) or 1 year (non-healthcare), transcripts the same, patients indefinitely, audit logs 6 years. All defaults are configurable, and you can honor individual deletion requests with the per-patient delete tool.3 min