HIPAA & BAABusiness Associate Agreement availableSigned before go-live

HIPAA & BAA

For the practices that handle PHI.

For the Customers we serve who handle protected health information, here is exactly what Book247 does to earn that trust.

Last updated August 17, 2026

1. Scope

This page is for the Customers we serve who are HIPAA Covered Entities, or who work with one, and use Book247 to handle protected health information (PHI) over phone, SMS, WhatsApp, chat or the booking widget: dental and orthodontic practices, med spas and aesthetics clinics, and physio and chiro practices, chiefly. Not every Book247 vertical touches PHI; veterinary and salons & barbers customers generally do not, since there is no human patient involved.

2. Business Associate status

The AI Leap, operating Book247, acts as a Business Associate under HIPAA when it creates, receives, maintains or transmits PHI on behalf of a Covered Entity Customer. For every Customer that needs one, we put a signed Business Associate Agreement in place before go-live, not after.

3. What counts as PHI here

In Book247's case, that's a patient's name and contact details, their appointment type and time, their assigned provider, and anything they say on a call or in a message that relates to their health, care or treatment.

4. Minimum necessary, by architecture

Book247's data model is deliberately minimal: name, phone, email, and what was booked. The Agent only ever asks for what it needs to identify the caller and book the visit. It does not ask for or store diagnosis detail, insurance card images, or any other record type outside that scope, and every industry Book247 serves shares the same generic customer, provider and service schema rather than a healthcare-specific superset that would invite collecting more than necessary.

5. Safeguards

Administrative. Access is role-based (owner, manager, staff, provider, viewer), a hidden button is never treated as a permission, and every new feature is checked against a documented incident-response runbook before it ships.

Physical. Book247 runs on infrastructure operated by our hosting and database providers, in access-controlled facilities; there is no self-hosted server holding customer data.

Technical. TLS and HSTS everywhere in transit; Postgres encryption at rest, with secrets and OAuth tokens additionally encrypted at the column level; every business's data is isolated from every other business's, enforced both at the application layer and by Postgres row-level security; internal endpoints are HMAC-signed and vendor webhooks are signature-verified before their contents are read; and personal data, phone numbers, emails, names, addresses, transcript text, is stripped by a redaction layer before it reaches application logs, error tracking, or the AI model provider's own logs.

6. Call recording

Off by default. A Customer must explicitly turn recording on, per location, which triggers a jurisdiction check for two-party consent requirements and switches on a mandatory notice at the start of the call, before recording begins.

7. Retention and disposal

Transcripts are kept 90 days, recordings 30 days, and cancelled-appointment records 24 months, enforced automatically by a nightly job rather than manual cleanup, so PHI does not linger past the window a Customer expects.

8. Subprocessors handling PHI

PHI may pass through Twilio (voice and SMS in the US, Canada, UK and Australia), MSG91 and Gupshup (SMS and WhatsApp in India), Vapi (voice AI infrastructure), and our hosting and database providers. Each is bound by its own agreement covering the data it touches, and we keep a current sub-processor list available on request.

9. Breach notification

If something goes wrong: contain it first, revoke credentials and disable the affected connector; assess what data, which Customers, and what window, using the audit log and message log as evidence; notify the Customer, and where the Customer directs, their patients, within the timeline HIPAA and other applicable regimes require; then remediate and publish a blameless postmortem with the regression test that would have caught it.

10. Patient rights

Customers can fulfill a patient's access, amendment or accounting-of-disclosures request using the self-serve export and delete tooling in account Settings, which cascades across appointments, conversations, transcripts and recordings.

11. Getting a BAA

Ask for one during onboarding, before go-live, or any time after, at security@book247.com. We'll issue the current Business Associate Agreement for signature alongside the standard Data Processing Agreement.

12. What this page isn't

This page describes how Book247 is built and operated. It doesn't replace a Customer's own HIPAA risk assessment, and it doesn't transfer the Customer's obligations as a Covered Entity to us; those stay with the Customer. See also our Privacy Policy and Terms of Service.

13. Contact

Security and compliance questions, including BAA requests: security@book247.com.