HIPAA
Healthcare outreach is one of the main things Neo Dialer is used for, so this page is deliberately specific about what is in place and what is not.
Last updated: 20 August 2026
Start here
If a covered entity or business associate uses Neo Dialer for calls that involve protected health information, we act as a business associate. That relationship requires a signed Business Associate Agreement, and calls involving PHI should not be run on the platform before one is in place. Contact us to start that conversation — tell us your use case and we will tell you plainly what we can execute.
We do not claim a HIPAA certification, because no such certification exists — HIPAA has no certifying body. What matters is the safeguards actually in place and the agreement signed. Both are covered below.
Safeguards the platform provides
Access control
- Unique user accounts with per-user roles; no shared logins
- Multi-factor authentication, which an organisation can require for all users
- Role-based access from agent through owner, enforced server-side so a user cannot reach records their role does not permit
- Support access only through an audited impersonation flow, visible to the tenant while it is happening
Audit controls
Administrative actions, sign-ins and support access are recorded in an audit log that tenant admins can review in-app, and which users cannot delete.
Integrity and transmission security
- TLS 1.2/1.3 for all web and API traffic, with HSTS
- Encryption at rest for the database and for recording storage
- Recordings held in per-tenant private buckets, reachable only via short-lived signed URLs — never a public link
- HMAC-signed, timestamped channels between the application and media servers, so captured requests cannot be replayed
Retention and disposal
Recording retention is configurable per tenant and capped by plan — 30 days on Starter, 90 on Growth, up to 365 on Enterprise. You choose what happens when the storage limit is reached. Data is deleted on request when an account closes.
What you must configure
Several safeguards depend on how you set the tenant up. None of these are on by default for every account:
- Minimum necessary. Give agents the narrowest role that lets them do their job, and keep PHI out of campaign contact fields that agents do not need.
- Recording consent. Configure whether calls are recorded and make sure your script obtains consent where the jurisdiction requires it.
- AI features. Transcription, call analysis and AI voice agents send call content to third-party AI vendors. If your BAA scope does not cover those vendors, keep those features disabled — the platform runs fully without them, and a self-hosted text-to-speech option exists for AI speech that avoids an external vendor.
- Retention. Set retention to the shortest period your programme allows, rather than leaving the plan maximum.
- Integrations. Anything you push to a CRM or calendar leaves our control and falls under your agreement with that vendor.
Healthcare features in the product
Beyond safeguards, the platform includes the pieces healthcare outreach usually needs: appointment reminder and confirmation campaigns, AI receptionists for inbound with business-hours and after-hours routing, callback scheduling, DNC enforcement, and QA scorecards and compliance checks over recorded calls. See Healthcare for how these fit together.
The honest summary
The technical safeguards are in place and described above. The organisational half — a signed BAA, an agreed sub-processor scope, and a tenant configured for minimum necessary — is a conversation, not a checkbox. Do not run PHI through the platform until that conversation has happened. Nothing on this page is a substitute for your own compliance assessment, and it is not legal advice.
Questions about this page, or need it in a form your legal team can sign? Contact us.