Our approach

SmartOps Health is built to operate as a HIPAA Business Associate to the medical practices we serve. That means we handle protected health information only to provide our services, under a signed agreement, and with administrative, physical, and technical safeguards designed around the HIPAA Security Rule.

Before any real patient data: we sign a Business Associate Agreement (BAA) with your practice, and our own subprocessors operate under BAAs, before any PHI flows through the platform.

Data protection

Access controls

Business Associate Agreements

We execute a BAA with every practice before handling PHI, and we maintain BAAs (or equivalent HIPAA-aligned terms) with the subprocessors that support the platform. A BAA is available on request.

Subprocessors

We rely on a small set of established infrastructure providers, engaged under appropriate data-protection and BAA terms where PHI is involved:

ProviderPurpose
Cloud hosting & application deliveryServing the application
Managed databaseEncrypted storage of practice and patient data
Telephony & SMSPatient calls and text reminders (with consent)
Voice AIOptional AI call assistant, under HIPAA-aligned terms

A current, detailed subprocessor list is available to customers on request.

Patient communications & consent

Text messages are sent only to patients who have opted in, in compliance with carrier (A2P 10DLC) and TCPA requirements. Every message includes clear opt-out instructions, and consent records are retained. See our Privacy Policy for details.

Clinical guardrails

Where the platform uses AI, it organizes and routes information; it does not diagnose, prescribe, or provide medical advice. A licensed clinician on your team reviews and acts on everything. This keeps decision-making with the care team, by design.

Incident response

We maintain procedures to detect, investigate, and respond to security incidents, and to notify affected practices consistent with HIPAA breach-notification requirements.

Where we are, honestly

SmartOps Health is an early-stage company building to HIPAA standards. We are transparent about our current posture: we sign BAAs, encrypt data in transit and at rest, enforce authenticated per-practice access, and keep clinicians at the center of every decision. As we grow, we are investing in formal third-party attestations. If your compliance team has specific requirements, we welcome the conversation.

Contact

Security or compliance questions? Email victoria@smartopshealth.com and we will respond promptly.