Overview
Company Periscope provides AI receptionist services to healthcare providers, including medical and dental practices. When our services are used to handle appointment scheduling, patient intake, insurance questions, or any communication that may involve protected health information ("PHI"), we act as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations, including the HIPAA Privacy, Security, and Breach Notification Rules.
Business Associate Agreement (BAA)
Before any PHI is processed on your behalf, we execute a Business Associate Agreement (BAA) with your practice. The BAA governs our permitted uses and disclosures of PHI, the safeguards we maintain, and our obligations in the event of a breach. A copy of our standard BAA is available upon request; contact support@companyperiscope.com and we will provide it for your review and signature.
How We Protect PHI
We apply administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI, including:
- Encryption of PHI in transit (TLS) and at rest
- Access controls that limit PHI to authorized personnel on a need-to-know basis
- Audit logging of access to systems that store or process PHI
- SOC 2-aligned infrastructure and vendor management for our subprocessors
- Workforce training on privacy and security responsibilities
Permitted Uses of PHI
We use and disclose PHI only as permitted by the BAA and as necessary to perform the services you have engaged us for, such as answering calls, scheduling appointments, routing messages, and configuring and improving the AI receptionist deployed for your practice. We do not sell PHI, and we do not use PHI for advertising.
Subprocessors
We may engage trusted service providers (for example, cloud infrastructure and telephony providers) to help deliver our services. Any subprocessor with access to PHI is bound by written agreements imposing HIPAA obligations consistent with our BAA with you.
Data Retention & Deletion
Call recordings and transcripts that may contain PHI are retained for a minimum of 90 days and up to 1 year unless a shorter period is requested or required by law. Upon termination of services, PHI is returned or securely destroyed in accordance with the BAA, except where retention is required by law.
Breach Notification
In the event of a breach of unsecured PHI, we will notify the affected covered entity without unreasonable delay and in accordance with the timelines and requirements of the HIPAA Breach Notification Rule and our BAA.
Patient Rights
HIPAA grants patients certain rights over their PHI, including rights of access and amendment. Because we act as a Business Associate rather than a covered entity, patients should direct such requests to their healthcare provider, who will coordinate with us as needed to fulfill them.
Contact Us
Questions about our HIPAA practices or to request a BAA? Contact us at support@companyperiscope.com. See also our Privacy Policy and Terms of Service.