PalmRoute is designed to support HIPAA-compliant operations for healthcare providers. Here's exactly how we protect your patients' data and yours.
Important Note for Healthcare Providers
PalmRoute can operate in a HIPAA-compliant manner for covered entities and business associates in healthcare. However, HIPAA compliance is only activated when you have an executed Business Associate Agreement (BAA) with PalmRoute. Using PalmRoute without a BAA to process Protected Health Information (PHI) is not compliant. To request a BAA, email hipaa@palmroute.com.
Our infrastructure and processes are designed to meet the rigorous standards required by healthcare providers operating under HIPAA.
SOC 2 Type II Infrastructure
Hosted on AWS, which maintains SOC 2 Type II, ISO 27001, and FedRAMP certifications.
AES-256 Encryption at Rest
All stored data including call recordings, transcripts, and PHI is encrypted using AES-256.
TLS 1.2+ in Transit
All data transmitted between your systems, callers, and PalmRoute is encrypted in transit.
Role-Based Access Controls
Access to PHI is restricted to authorized personnel only, with full audit logging of all access events.
Business Associate Agreement
We execute a HIPAA-compliant BAA with every healthcare provider client upon request.
Annual Security Audits
Independent third-party penetration testing and security audits performed annually.
The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law that establishes national standards for the protection of individuals' medical records and other individually identifiable health information. It applies to:
HIPAA sets requirements for administrative, physical, and technical safeguards to protect the privacy and security of PHI. The HITECH Act strengthened HIPAA enforcement and extended certain obligations to business associates.
PHI is any individually identifiable health information — transmitted or maintained in any form — that relates to:
This includes 18 specific identifiers when combined with health information, such as:
When patients call your practice through PalmRoute's AI assistant and share appointment requests, symptoms, or any health-related information, that data may constitute PHI and must be handled in accordance with HIPAA.
When you use PalmRoute to handle calls for a healthcare practice, PalmRoute acts as a Business Associate under HIPAA. This means:
PalmRoute will not use or disclose PHI except as permitted by the BAA and as required by law. We will not sell PHI or use it for marketing or advertising purposes.
A Business Associate Agreement is a legally required contract between a covered entity and its business associate. Our BAA covers:
Our BAA template is available upon request and is consistent with the DHHS model BAA provisions. You may propose modifications, and we will work with you to reach an agreement appropriate for your practice.
Encryption at Rest
All PHI stored using AES-256 encryption. Encryption keys are managed separately from encrypted data.
Encryption in Transit
All communications secured with TLS 1.2 or higher. HSTS enforced on all web endpoints.
Access Controls
Role-based access controls, multi-factor authentication required for all internal staff, principle of least privilege enforced.
Audit Logging
All access to PHI is logged with user identity, timestamp, and action. Logs are retained for 6 years.
Backup & Redundancy
Daily encrypted backups stored in geographically separate AWS regions. 99.9% uptime SLA.
Vulnerability Management
Continuous vulnerability scanning, annual penetration testing by independent security firms, rapid patching protocols.
PalmRoute uses the following sub-processors that may process PHI when you have an active BAA with us. Each sub-processor has executed a HIPAA-compliant BAA with PalmRoute:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting & storage | USA |
| Twilio | Voice & SMS communications | USA |
| SendGrid | Transactional email delivery | USA |
| Stripe | Payment processing (billing only, no PHI) | USA |
We will notify you of any changes to our sub-processor list at least 30 days in advance. You may object to any new sub-processor by terminating your subscription within that 30-day window.
In the event of a breach of unsecured PHI, PalmRoute will:
To report a suspected breach or security incident, contact our Security team immediately at security@palmroute.com or call +1 (555) 823-4567.
HIPAA grants patients certain rights over their PHI. As your business associate, PalmRoute will support you in honoring these rights:
Patients should direct all privacy requests to your practice directly. We will support you in fulfilling those requests within required timeframes.
With an executed BAA, PalmRoute's AI can support your healthcare practice with:
For all HIPAA-related inquiries, BAA requests, breach reports, or compliance questions:
Additional HIPAA resources:
Request your BAA and book a demo. We'll walk you through exactly how PalmRoute works within HIPAA requirements for your practice type.