Skip to main content

How We Protect Patient Data

Updated over a month ago

Allia Health is a HIPAA-compliant and SOC 2 Type II compliant EHR. We utilize a "Zero-Access" architecture, which means your practice data and clinical records are encrypted so that only you can access them.

How We Protect Your Data

Our security framework is built on the principle of end-to-end technical isolation to exceed standard regulatory requirements.

  • HIPAA & SOC 2 Compliance: Every aspect of our data handling—from ingestion to storage—is governed by HIPAA regulations and SOC 2 Type II security principles.

  • Encryption at Source: Clinical notes and session data are encrypted locally on the provider’s device before being transmitted to our infrastructure.

  • Decryption Authority: Decryption keys are held solely by the authorized provider. Allia Health does not possess the technical means to read, access, or decrypt clinical data.

  • Legal Data Isolation: Because Allia Health does not hold decryption keys, the system is architecturally incapable of providing clinical data to third parties, including healthcare organizations or legal entities.

Telehealth Transcription & AI

We use AI to help you with notes, but we do it with a "privacy-first" approach.

  • Audio is Never Saved: During telehealth, we convert speech to text in real-time. Once the text is made, the audio is instantly deleted.

  • Patients Must Agree: For telehealth encounters transcription only turns on if your patient clicks "I Consent" at the start of the session. If they say no, it stays off.

  • No AI Training: We never use your notes to train or "teach" AI models. Your clinical wisdom stays private.

  • It’s Optional: You decide which AI features to use. Nothing is forced.

You Own Your Records

You are never "locked in" to Allia. You own your data 100%.

  • Easy Export: Download all your notes and records with one click at any time.

  • 7-Year Safety: We keep records for 7 years to help you stay compliant with state and federal laws.

  • Total Deletion: If you delete a note or close your account, it’s gone forever. We don’t keep "shadow copies."

Compliance & Support

Did this answer your question?