We protect the health information your clinic shares with us.
Between-visit texts and visit summaries can include names, replies, and light care context. We treat that as protected health information from day one. BAA at signup. US servers. Published controls. Not a certification wish list.
- HIPAA Security program
- BAA Signed at signup
- Encrypted In transit & at rest
- US-only Infrastructure
- SOC 2 Type II Underway
Core commitments
How we protect PHI.
-
Encryption & US servers
Encrypted while moving through Helose systems and while stored. Patient health information stays on servers in the United States.
-
Only what we need
We collect what is needed for check-ins, reorders, and visit summaries. We do not sell your data, train models on patient health information, or use it for advertising.
-
Clinics stay separate
Each clinic's patients stay in their own workspace. Staff only see what their job requires. Reads are logged. Clinics cannot see each other's data.
-
Your data, your clinic
Export on cancel. Delete within 30 days. Certificate of destruction on request. Audit logs per your BAA.
PHI surfaces
Where PHI can show up.
One BAA covers check-in texts, portal flows, staff queues, and the pre-visit summary. Same isolation, encryption, and audit logging everywhere.
-
Patient-facing
Patient texts
Health info in scopeMessage bodies and replies live in the patient thread on your clinic number. Staff approve the playbook once from a fixed template list. Helose runs those texts on schedule. Staff step in for exceptions. Texts stay short: check-ins, reorder prompts, simple replies. When more detail is needed, patients get a link to a secure page (or a short "you have a message" notice). Not for diagnoses or emergency triage.
-
Clinic-facing
Pre-visit summary
Health info in scopeThe summary your team opens before the visit combines the last visit plan, check-in replies, and portal activity (including reorder confirms). Clinical interpretation stays with your clinicians.
In place today
Controls on every text and visit summary.
-
HIPAA security program
Administrative, physical, and technical safeguards aligned to the HIPAA Security Rule. BAA with Helose required before patient health information is in scope.
-
Encryption
Standard encryption while data moves through Helose systems and while it is stored. Patient phones may still show lock-screen previews. Standard cellular texts are not always encrypted end to end on the path to the device.
-
Staff approval & fixed templates
Outbound health-related texts require clinic staff approval. Starts come from a fixed message list so content stays short and easier to keep within your consent rules.
-
Clinics stay separate
Database controls keep each clinic's patients in their own workspace. One clinic cannot read another's patients.
-
Audit logging
Tamper-evident audit log records reads and messaging actions. Logs are retained for seven years per our data retention policy, then destroyed per your BAA.
-
HIPAA Security Risk Assessment
Completed and maintained on a regular review cycle. Summary available on request.
Compliance detail
BAA, TCPA, and complaints.
Expand only what you need. Full legal detail stays here, not spread across the scroll.
Business Associate Agreement
Helose is a business associate when your clinic uses between-visit texting or pre-visit summaries. Patient health information requires a current BAA on file with Helose.
- Click-through BAA at clinic signup, before any patient health information moves. Built for practices that want to start quickly.
- Hospital-affiliated and enterprise buyers can request a counter-signed BAA on Helose letterhead before go-live. Ask sales; do not wait until PHI is already in the product.
- BAA template and security documentation available on request.
- Certificate of destruction available when your clinic terminates service.
Clinic obligations
Helose is your business associate. You remain the covered entity, responsible for consent, message content, and honoring STOP requests.
- Obtain valid patient consent before sending health-related texts (federal TCPA, your Notice of Privacy Practices, and any stricter state rules). At opt-in, tell patients that agreeing to texts is not required to receive care. Include that message frequency varies, plus STOP, HELP, and message-and-data-rates language.
- Reorder or refill nudges that read as promotional may need prior express written consent. Ask your counsel for the states where you practice.
- Keep message content appropriate: short check-ins and reorder prompts from the fixed template list, not diagnoses, lab results, or emergency triage in the thread.
- Use secure web pages (or a short "you have a message" link) when richer detail is needed; keep texts brief.
- Honor STOP and opt-out requests promptly.
- Own the patient relationship. Helose provides the texting tools; your clinic is the covered entity.
- Maintain accurate patient phone numbers and update records when patients change numbers.
SMS & TCPA
Helose is your business associate for messaging technology. Consent under the TCPA, state messaging rules, and message content remain your responsibility as the covered entity.
- Document consent before the first health-related text, written or electronic per your counsel's guidance.
- At opt-in, disclose that texts are not required to receive care, that message frequency varies, STOP/HELP, and message-and-data rates. Share Messaging Terms (/sms-terms).
- Do not use texts for marketing without the consent level that law requires. Refill-class nudges can tip into marketing depending on wording.
This is operational guidance, not legal advice. Consult your counsel for TCPA and state-specific requirements.
Privacy complaints
Individuals have the right to file a privacy complaint with the U.S. Department of Health and Human Services Office for Civil Rights (OCR), and may also contact Helose or their clinic, per HIPAA §164.530(d).
- File with HHS Office for Civil Rights at hhs.gov/ocr.
- Or email Helose with your clinic name and a description of the concern (privacy@helose.com).
- We aim to acknowledge complaints we receive within five business days and investigate per our HIPAA Privacy Policy.
Your data
Lifecycle, step by step.
-
What we receive
Patient identifiers, message content and replies, schedule details, and the context your team needs in the pre-visit summary. Only what is required to run check-ins, reorders, and summaries for your clinic.
-
What we use it for
Staff-approved check-in texts, reorder confirms, and staff queues. Visit summary for your team. Audit trail for your compliance team. Nothing else.
-
Where it lives
Patient health information stays on servers in the United States. Encrypted while moving through Helose systems and while stored.
-
If you leave
Cancel anytime. We export your data in a portable format and delete it from our systems within 30 days. A certificate of destruction is available on request. Audit logs are retained per your BAA (up to seven years), then destroyed per your agreement.
De-identified data. We may use properly de-identified, aggregated data to improve product accuracy and publish benchmarks. Details are in your BAA and available on request.
Patient-facing detail: Data & privacy Messaging terms
FAQ
Questions clinics ask first.
Does Helose sell our data?
Does Helose use our PHI to train models?
What is your SOC 2 status?
When is the BAA signed?
Where does our data live?
Are patient texts encrypted end to end?
What happens to our data if we cancel?
Can we get detailed security documentation?
Need receipts?
Security questionnaires are typically turned around within five business days. Detailed documentation available on request.