HIPAA Compliant

DeskPilot is HIPAA-Ready for Healthcare Practices

Built from the ground up with technical safeguards, audit logging, breach notification procedures, and Business Associate Agreements for dental, medical, and VA practices.

Sign the BAA
πŸ”

Transmission Security

TLS 1.2+ enforced on all endpoints. HSTS enabled. All data in transit is encrypted.

πŸ“‹

Audit Logging

Append-only PHI access logs with 6-year retention. Every read, write, and delete recorded.

πŸ›‘οΈ

Access Controls

Role-based access. Customer and admin domains strictly separated. No PHI exposed via public endpoints.

πŸ“„

BAA Available

Business Associate Agreements executed digitally with timestamped, IP-verified signatures.

Encryption at Rest and in Transit

DeskPilot implements HIPAA's technical safeguards as required under 45 CFR Β§164.312.


Complete Audit Trail for All PHI Access

DeskPilot maintains an append-only audit log of all activity involving Protected Health Information. Logs cannot be deleted or modified β€” HIPAA requires 6-year retention and we enforce it at the database level.


Least-Privilege Access Architecture

DeskPilot enforces strict domain-based access separation. PHI is only accessible to authenticated users with a legitimate business need.


Breach Detection and 60-Day Notification

DeskPilot maintains automated breach detection and a documented incident response procedure in compliance with the HIPAA Breach Notification Rule.

Incident Response Contact: To report a suspected security incident, contact security@deskspilot.net. Our team will acknowledge within 24 hours and provide an initial assessment within 48 hours.

BAA Execution for Covered Entities

Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on behalf of a Covered Entity must execute a Business Associate Agreement. DeskPilot qualifies as a Business Associate when used by healthcare providers.

BAA included at no extra cost. DeskPilot provides a full HIPAA-compliant BAA to all healthcare customers. The agreement covers permitted uses of PHI, required safeguards, breach notification obligations, and termination provisions.

Built for Dental, Medical, and VA Practices

DeskPilot includes purpose-built HIPAA-compliant AI scripts for three healthcare verticals, each with appropriate emergency protocols and PHI-minimum collection workflows.


What DeskPilot Covers vs. What You're Responsible For

HIPAA compliance is a shared responsibility between DeskPilot (Business Associate) and your practice (Covered Entity).

Note: DeskPilot's HIPAA compliance does not cover uses of the service outside the healthcare workflows documented here. General business scheduling use does not involve PHI handling.

Ready to use DeskPilot for your practice?

Sign the BAA digitally in under 2 minutes. No paper, no waiting β€” just your name, email, and practice information.

Sign the BAA Contact Security Team

This page describes DeskPilot's HIPAA compliance posture as of May 4, 2026. HIPAA compliance information is subject to change as regulations and our technical infrastructure evolve. For questions about our compliance program, contact security@deskspilot.net. Nothing on this page constitutes legal advice β€” consult your own counsel for compliance determinations specific to your practice.