Our approach
SmartOps Health is built to operate as a HIPAA Business Associate to the medical practices we serve. That means we handle protected health information only to provide our services, under a signed agreement, and with administrative, physical, and technical safeguards designed around the HIPAA Security Rule.
Data protection
- Encryption in transit: all traffic is served over HTTPS/TLS.
- Encryption at rest: patient data is stored in an encrypted, access-controlled database.
- Minimum necessary: the platform surfaces only the information a task requires.
- No sale or marketing use of PHI: we never sell, rent, or share patient information for marketing.
Access controls
- Authenticated access only: every user signs in; there is no anonymous access to patient data.
- Practice-level isolation: the platform is multi-tenant, and each practice's data is scoped to that practice. Users only see their own practice's patients.
- Role-based permissions: administrative functions (staff management, billing, onboarding) are limited to authorized roles.
- Audit logging: access to patient records and key actions are logged.
Business Associate Agreements
We execute a BAA with every practice before handling PHI, and we maintain BAAs (or equivalent HIPAA-aligned terms) with the subprocessors that support the platform. A BAA is available on request.
Subprocessors
We rely on a small set of established infrastructure providers, engaged under appropriate data-protection and BAA terms where PHI is involved:
| Provider | Purpose |
|---|---|
| Cloud hosting & application delivery | Serving the application |
| Managed database | Encrypted storage of practice and patient data |
| Telephony & SMS | Patient calls and text reminders (with consent) |
| Voice AI | Optional AI call assistant, under HIPAA-aligned terms |
A current, detailed subprocessor list is available to customers on request.
Patient communications & consent
Text messages are sent only to patients who have opted in, in compliance with carrier (A2P 10DLC) and TCPA requirements. Every message includes clear opt-out instructions, and consent records are retained. See our Privacy Policy for details.
Clinical guardrails
Where the platform uses AI, it organizes and routes information; it does not diagnose, prescribe, or provide medical advice. A licensed clinician on your team reviews and acts on everything. This keeps decision-making with the care team, by design.
Incident response
We maintain procedures to detect, investigate, and respond to security incidents, and to notify affected practices consistent with HIPAA breach-notification requirements.
Where we are, honestly
SmartOps Health is an early-stage company building to HIPAA standards. We are transparent about our current posture: we sign BAAs, encrypt data in transit and at rest, enforce authenticated per-practice access, and keep clinicians at the center of every decision. As we grow, we are investing in formal third-party attestations. If your compliance team has specific requirements, we welcome the conversation.
Contact
Security or compliance questions? Email victoria@smartopshealth.com and we will respond promptly.