HIPAA and the BAA
In normal use, patient data stays entirely inside your office, so most practices never need a BAA with us. Here is where the data goes, and the one case where a BAA applies.
Where patient data goes
- Voice never leaves the device it was spoken into. Speech recognition runs on the phone, or on the operatory computer when the clinician uses its microphone.
- Chart values move phone to computer on your own network. The connection is encrypted with TLS 1.2/1.3 and pinned to the office computer’s certificate. Chart data never passes through PerioMaxer’s cloud.
- Our cloud holds your account, not your patients. We store your practice name, billing, plan, and activation keys. We hold no patient data. That is the architecture, not just a policy.
- Updates are cryptographically signed. The desktop refuses unsigned updates.
When a BAA applies: the network relay
Charting needs the phone and the office computer on the same network. Some offices cannot put them on one network. For those offices only, we plan to relay charting traffic through our servers. That would make us a business associate under HIPAA, so we sign a BAA with the practice first, then turn the relay on for your account once it ships.
If your office needs it, email support@periomaxer.com and we will tell you where it stands. The BAA exists only for this relay case. It is not part of normal setup.
What we keep when you cancel
- Your computers stop charting right away.
- Billing records are kept as tax law requires.
- Your practice profile (name, address) can be deleted on request.
- Your patient data is unaffected. It lives in your practice software and was never on our servers.