Minimum necessary
The receptionist asks for identity, a callback number and the concern. It does not fish for anything else, and it never diagnoses or advises.
Security
Built for a practice that is accountable for every record. The receptionist collects what a call needs, keeps it where it belongs, and leaves a trail.
The receptionist asks for identity, a callback number and the concern. It does not fish for anything else, and it never diagnoses or advises.
Appointment confirmations omit the clinical reason. Escalation alerts contain an expiring link; clinical summaries remain behind access controls. Review message content and delivery settings with your practice.
Data is encrypted in transit and at rest. Every read of a transcript is written to the audit log with who, when and which call.
Recording is off by default. Where a practice turns it on, the caller is told, and the policy is enforced per call.
Real calls feed the learning set only after de-identification to the Safe Harbor standard, and only for practices that allow it in writing. Retention is 365 days; a record can be erased on request.
Staff sign in by email code and a second factor. Front desk, on-call, manager and reviewer roles see only what they need; a role that should not see a screen is told it does not exist.
A BAA is part of onboarding for every practice, and the platform is deployed so that call audio and records stay with providers covered by it.
The dashboard holds operational call records, tasks, and its schedule. EHR connections are validated during onboarding. Document what is synchronized and what your staff must reconcile.
Your privacy and security leads should review the agreements and the configured service together.
Review the BAA, permitted uses, incident reporting, and the vendors that handle audio and records. HHS explains the obligations of business associates and their subcontractors.
Confirm staff roles, second-factor sign-in, and who can open transcripts or recordings. Ask to see an access event in the audit log.
Document the region, recording policy, retention periods, and deletion procedure for your deployment. Confirm whether learning is enabled and what written permission covers it.
Approve the escalation protocol and verify every destination with a test call. A compliance claim does not replace your review of the service, its agreements, and your operating procedures.
Review the Business Associate Agreement, which vendors process call audio and records, where data is stored, staff access, audit logs, recording policy, retention, deletion, and incident reporting. Callinzo's onboarding includes a BAA and practice-specific configuration. Compliance depends on the agreements, deployment, and operating procedures together; a website label or encryption alone is not enough. Your privacy and security leads should review the actual arrangement before patient calls begin.
In the region you choose at onboarding, on infrastructure covered by the agreements above. The learning set, where enabled, is kept in a separate store per region.
Only roles the practice allows, and every access is logged. Where recording is off, there is nothing to listen to.
Yes. Records can be erased from the learning set on request, and the practice controls retention of call records.
Every control above is visible in the dashboard: the audit log, the recording policy, the learning consent and the retention window.