Last Updated
January 14, 2026
Market Region
USA / Federal
OrapexAI is built from the ground up to meet the compliance requirements of dental practices under HIPAA and the HITECH Act. Every component of our platform — from the first ring of a patient call to the final appointment confirmation — is designed to keep Protected Health Information (PHI) secure, private, and fully compliant.
As a dental practice, you are a HIPAA Covered Entity. When you use OrapexAI to handle patient calls, we act as your Business Associate — a role we take seriously. We understand that your patients trust you with their most sensitive health information, and by extension, they are trusting the tools you choose to work with.
OrapexAI is committed to ensuring that your use of our AI receptionist service never puts your practice, your patients, or your reputation at risk. We have implemented administrative, technical, and physical safeguards that satisfy the requirements of the HIPAA Security Rule, Privacy Rule, and the HITECH Act.
Before any patient data is ever processed through OrapexAI, we execute a signed Business Associate Agreement (BAA) with your practice. This is a legal requirement under HIPAA, and we make it a non-negotiable part of our onboarding process — no exceptions.
The BAA formally establishes:
OrapexAI processes only the minimum necessary PHI required to perform your requested services. This includes:
We do not access, store, or process clinical records, treatment notes, diagnoses, prescriptions, or any PHI beyond what is strictly necessary for the receptionist functions you have contracted us to perform.
This is a firm policy: OrapexAI does not use any Protected Health Information — including call recordings, transcripts, patient names, or insurance details — to train, fine-tune, or improve any artificial intelligence or machine learning model. Any improvements to our system are based exclusively on anonymized, non-identifiable operational metadata that cannot be traced back to any individual patient or practice.
Our infrastructure is designed with HIPAA Security Rule requirements as a baseline, not an afterthought. Key safeguards include:
Encryption in Transit
All data transmitted between patients, our systems, and your practice management software is encrypted using TLS 1.2 or higher.
Encryption at Rest
All stored PHI — including call recordings and transcripts — is encrypted at rest using industry-standard AES-256 encryption.
Access Controls
Access to PHI is governed by role-based permissions and the principle of least privilege. Only authorized systems may interact with patient data.
Audit Logging
All access to and interactions with PHI are logged and auditable, providing a complete trail for compliance reviews or breach investigations.
Vulnerability Management
We conduct regular security assessments and promptly remediate identified vulnerabilities in our platform.
Subcontractor Compliance
All third-party service providers that may have access to PHI in the course of service delivery are contractually required to maintain equivalent HIPAA-compliant safeguards.
PHI processed through OrapexAI is retained only for as long as necessary to fulfill the purpose for which it was collected, or as required by applicable law. Specifically:
In the unlikely event of a confirmed or suspected breach involving PHI, OrapexAI will notify your practice without unreasonable delay — and in no case later than 60 days after discovery — consistent with HIPAA breach notification requirements. Our notification will include the nature of the breach, the PHI involved, the steps we have taken to contain and remediate the incident, and our recommendations for any actions your practice should take to protect your patients.
While OrapexAI takes on significant compliance obligations as your Business Associate, your practice retains responsibility for certain aspects of HIPAA compliance, including:
If you have questions about our HIPAA compliance practices, wish to review our BAA before signing up, or need to report a suspected security incident, please contact us directly:
OrapexAI Compliance
hello@orapexai.com
We aim to respond to all compliance-related inquiries within 1 business day.
Contact our US-based legal team.