Security, compliance, and data protection are the foundation of everything we build. ChiroDesk AI is designed from the ground up for healthcare, so you can trust us with your patients' data.
Continuously monitored · Independently audited
Full technical, administrative, and physical safeguards for protected health information.
CompliantIndependent audit of security, availability, and confidentiality controls.
Controls ImplementedConsent management and compliance for all outbound patient communications.
CompliantBusiness Associate Agreement signed with every practice before any data is shared.
IncludedHow we implement technical, administrative, and physical safeguards to protect PHI.
Public View document ›How we collect, use, and protect your information.
Public View document ›The terms governing use of our platform and services.
Public View document ›How our Business Associate Agreement protects your patient data.
Public View document ›| Company | Purpose | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure & data storage | United States |
| Twilio | Telephony & SMS | United States |
| ElevenLabs | Voice synthesis | United States |
| Anthropic | AI language processing | United States |
| Stripe | Payment processing | United States |
| Postmark | Transactional email | United States |
| Datadog | Infrastructure monitoring & logging | United States |
Subscribe to subprocessor change notifications: security@chirodesk.ai
ChiroDesk AI is hosted on enterprise-grade U.S.-based cloud infrastructure with:
Uptime SLA: 99.9% target availability for all production services.
Yes. All patient data is encrypted with AES-256 at rest and TLS 1.3 in transit. Every call recording, transcript, text message, and database record is encrypted end-to-end. Encryption keys are managed through AWS KMS with automatic rotation.
No. Patient data is never used to train, fine-tune, or improve any AI models. Your data is used exclusively to provide the scheduling service to your practice. This is contractually guaranteed in our BAA and Terms of Service.
We maintain a comprehensive incident response plan that includes immediate containment, investigation, and notification. In the event of a breach affecting PHI, we will notify affected practices within 24 hours and work with you on required patient notifications per HIPAA Breach Notification Rule requirements.
All data is stored in SOC 2 certified Amazon Web Services (AWS) data centers located in the United States (us-east-1 and us-west-2 regions). Data never leaves U.S. borders. Each practice’s data is logically isolated. One practice can never access another’s information.
Upon cancellation, you have 60 days to export your data. After that, all data is permanently deleted from our systems, including backups. We provide written confirmation of data destruction upon request.
For security inquiries, compliance questions, or to request documentation:
Email: security@chirodesk.ai
To report a security vulnerability, please email security@chirodesk.ai with details. We take all reports seriously and will respond within 24 hours.