HIPAA and your data

In normal use, patient data stays entirely inside your office, so most practices never need a BAA with us. Here is where the data goes, and the one case where a BAA applies.

Where patient data goes

  • Voice never leaves the device it was spoken into. Speech recognition runs on the phone, or on the operatory computer when the clinician uses its microphone.
  • Chart values move phone to computer on your own network. The connection is encrypted with TLS 1.2/1.3 and pinned to the office computer’s certificate. Chart data never passes through PerioMaxer’s cloud.
  • Our cloud holds your account, not your patients. We store your practice name, billing, plan, and which computers are signed in. We hold no patient data. That is the architecture, not just a policy.
  • Updates are cryptographically signed. The desktop refuses unsigned updates.

When charting goes through the internet

Charting needs the phone and the office computer on the same network. Some offices cannot put them on one network. For those offices only, charting can be carried through our servers. That makes us a business associate under HIPAA, so we put a Business Associate Agreement in place with the practice first, then turn it on for your account.

If your office needs it, open a support request from your portal or email support@periomaxer.com and we will work through it with you. Nothing about it is part of normal setup.

What we keep when you cancel

  • Your computers stop charting right away.
  • Billing records are kept as tax law requires.
  • Your practice profile (name, address) can be deleted on request.
  • Your patient data is unaffected. It lives in your practice software and was never on our servers.