All PHI is encrypted in transit using TLS 1.2 or higher. All PHI is encrypted at rest using AES-256. There is no path through our systems where PHI travels or sits in plaintext — including internal service-to-service traffic, database storage, backups, and log archives.
HIPAA-compliant. BAA-ready.
Our agents touch protected health information every day — voice calls with patients, eligibility checks against payer systems, appointment confirmations by SMS. Every safeguard required by HIPAA is in place before we exchange a single record. A signed Business Associate Agreement is the standard, not the exception.
Built for healthcare from the first line of code.
Sage Health operates as a Business Associate under HIPAA. The voice, SMS, and eligibility agents we deploy receive, transmit, and store protected health information on behalf of the practices we serve. That responsibility shapes every architecture decision we make.
We sign a Business Associate Agreement (BAA) with every practice before any PHI is exchanged. Our administrative, physical, and technical safeguards meet the HIPAA Security Rule; our breach response procedures meet the Breach Notification Rule. Both are operationalized — not paperwork sitting in a binder.
The same compliance posture that hospital systems demand from their vendors is the posture independent practices get from Sage Health. Without the multi-quarter procurement cycle, and without the price tag.
Four technical safeguards. Always on.
Encryption, access control, audit logging, and network isolation aren't features we add — they're the baseline every agent runs on, every day, by default.
Access to systems that handle PHI follows the principle of least privilege. Multi-factor authentication is required for every team member with production access. Role-based controls limit what each role can see and do. Access is reviewed quarterly and revoked the day a team member's role changes.
Every access to PHI is logged — who accessed what, from where, and when. Logs are stored in append-only storage, retained for six years to satisfy HIPAA, and monitored for anomalies. If a practice asks us to produce an access record for a specific patient, we can.
Production systems run inside private network segments with no direct public exposure. Inbound traffic flows through hardened gateways. Outbound traffic is restricted to known integrations — your EHR, your phone provider, payer eligibility endpoints. Nothing else.
A BAA before the first call. Every time.
A BAA is the contract HIPAA requires between a covered entity and its business associates. We've already drafted ours. You can have it before our second meeting.
Our BAA is built around the standard required clauses — permitted uses and disclosures, safeguards, subcontractor obligations, breach notification timelines, and termination rights. We've kept the language plain. There are no surprise carve-outs and no clauses written to limit our accountability.
- Available on request, executed before any PHI exchange. No waiting period, no minimum contract value, no procurement ceremony.
- Covers every Sage Health service. One BAA spans all the agents we run for you — voice, SMS, eligibility, BI — and any service we add later.
- Subcontractor flow-down handled. Every infrastructure provider and downstream vendor that touches PHI has a BAA with us. You get one agreement; we manage the chain.
- Mutual breach notification. Defined timelines, defined responsibilities, defined point of contact on both sides — so if something happens, no one is figuring out who calls whom.
Reviewing the BAA with your counsel? We welcome redlines. Most practices return ours unchanged; some negotiate language around indemnification or audit rights. We respond within two business days. Request a copy
Minimum necessary. US-based. Yours to delete.
HIPAA's "minimum necessary" standard isn't a guideline for us — it's the rule that governs what we collect, where it lives, and how long we keep it.
Only what each agent needs to do its job. Voice agent: caller phone number, conversation transcript, the appointment context it's negotiating. Eligibility agent: the patient demographics and insurance fields the payer requires. We do not collect clinical notes, lab results, or anything outside the operational scope of the agent.
All PHI is stored in US-based AWS regions. PHI never leaves the United States. Backups are encrypted and stored in a second US region for resilience. We do not process or store PHI on team members' laptops — production systems are the only place PHI sits.
Operational data is retained for the period defined in your practice agreement — typically the duration of the engagement plus the period your state's medical record retention rules require. Audit logs are retained six years per HIPAA. On termination, we return or destroy PHI per the BAA, with a written certificate of destruction.
The same controls hospital systems demand from their vendors.
Sage Health runs on AWS infrastructure built and operated to healthcare standards — the same foundation that hospital systems, payers, and EHR vendors rely on.
All compute, storage, and managed services run in AWS US regions covered by AWS's HIPAA-eligible services list. AWS holds a SOC 2 Type II attestation, ISO 27001 certification, and HITRUST certification — and operates under a signed BAA with Sage Health. We inherit those controls and operate our own on top.
Our internal control program is designed against the SOC 2 Type II framework — security, availability, confidentiality. Access reviews, change management, vulnerability scanning, and vendor risk assessment all run on defined cadences. We don't claim a certification we don't yet hold; we operate as if we already do.
Object storage (S3) uses server-side encryption with AES-256. Block storage (EBS) is encrypted with customer-managed keys rotated annually. Database backups are encrypted with the same standards as primary storage, replicated across availability zones, and tested with periodic restore drills.
Infrastructure logs, application logs, and PHI access logs flow into a centralized monitoring stack. Alerts fire on anomalous access patterns, configuration drift, and known indicators of compromise. The on-call rotation is staffed every day of the year.
Technology is half of HIPAA. The other half is people.
Every team member who could ever touch a system that handles PHI is trained, screened, and bound by the same standards our technology meets.
Every team member completes HIPAA Privacy and Security Rule training before they receive access to any production system. Refreshers run annually. Role-specific training covers the systems each person operates — voice agent operators, BI analysts, infrastructure engineers — so the training maps to the work, not just the regulation.
We maintain a documented incident response plan with defined severity tiers, response timelines, and customer notification procedures. In the event of a security incident involving PHI, affected practices are notified in accordance with HIPAA Breach Notification Rule timelines — with the facts we have, in plain language, as soon as we have them.
Every vendor that could touch PHI — our cloud provider, telephony provider, eligibility clearinghouse — is under a signed BAA with Sage Health, vetted on a security questionnaire, and reviewed annually. New vendors don't enter the chain until they've cleared the same gate.
Our HIPAA policies and procedures — risk assessment, access management, incident response, sanction policy, contingency planning — are documented, version-controlled, and reviewed annually by our security lead. We can share the policy index under NDA during procurement review.
Move fast without lowering the bar.
Independent practices shouldn't have to choose between modern technology and a strong compliance posture. Sage Health was built to remove that trade-off.
When you sign with us, you get the agents and the BI dashboard you came for — and you also get a partner who already meets the HIPAA bar, signs the BAA on day one, and can answer your compliance officer's questions with a real document, not a pitch deck. That's the floor we operate from.
Let's build together.
Independent practices deserve intelligent practice operations. Get started with a quick conversation.