Skip to main content

How we protect patient data

Learn how Allia protects clinical data, handles telehealth transcription and AI, and gives you control of patient records.

Allia Health is a HIPAA-compliant and SOC 2 Type II compliant EHR. Allia uses a "Zero-Access" architecture. Your practice data and clinical records are encrypted so that only you can access them.

How Allia protects your data

Allia uses end-to-end technical isolation to exceed standard regulatory requirements.

  • HIPAA and SOC 2 compliance: Data handling, from ingestion to storage, is governed by HIPAA regulations and SOC 2 Type II security principles.

  • Encryption at the source: Clinical notes and session data are encrypted locally on the provider’s device before they are sent to Allia’s infrastructure.

  • Decryption authority: Only the authorized provider holds the decryption keys. Allia Health cannot read, access, or decrypt clinical data.

  • Legal data isolation: Because Allia Health does not hold the decryption keys, Allia cannot provide clinical data to third parties, including healthcare organizations or legal entities.

Telehealth transcription and AI

Allia uses a privacy-first approach when AI helps with notes.

  • Audio is never saved: During telehealth, Allia converts speech to text in real time. The audio is deleted as soon as the text is created.

  • Patients must agree: Telehealth transcription starts only after the patient selects I Consent at the beginning of the session. If the patient does not consent, transcription stays off.

  • No AI training: Allia never uses your notes to train AI models.

  • AI is optional: You choose which AI features to use.

You own your records

You own your data and are not locked into Allia.

  • Easy export: Download all your notes and records with one click at any time.

  • Seven-year retention: Allia keeps records for seven years to help you comply with state and federal laws.

  • Total deletion: If you delete a note or close your account, the data is permanently deleted. Allia does not keep shadow copies.

Privacy and security support

Did this answer your question?