Allia Health is a HIPAA-compliant and SOC 2 Type II compliant EHR. Allia uses a "Zero-Access" architecture. Your practice data and clinical records are encrypted so that only you can access them.
How Allia protects your data
Allia uses end-to-end technical isolation to exceed standard regulatory requirements.
HIPAA and SOC 2 compliance: Data handling, from ingestion to storage, is governed by HIPAA regulations and SOC 2 Type II security principles.
Encryption at the source: Clinical notes and session data are encrypted locally on the provider’s device before they are sent to Allia’s infrastructure.
Decryption authority: Only the authorized provider holds the decryption keys. Allia Health cannot read, access, or decrypt clinical data.
Legal data isolation: Because Allia Health does not hold the decryption keys, Allia cannot provide clinical data to third parties, including healthcare organizations or legal entities.
Telehealth transcription and AI
Allia uses a privacy-first approach when AI helps with notes.
Audio is never saved: During telehealth, Allia converts speech to text in real time. The audio is deleted as soon as the text is created.
Patients must agree: Telehealth transcription starts only after the patient selects I Consent at the beginning of the session. If the patient does not consent, transcription stays off.
No AI training: Allia never uses your notes to train AI models.
AI is optional: You choose which AI features to use.
You own your records
You own your data and are not locked into Allia.
Easy export: Download all your notes and records with one click at any time.
Seven-year retention: Allia keeps records for seven years to help you comply with state and federal laws.
Total deletion: If you delete a note or close your account, the data is permanently deleted. Allia does not keep shadow copies.
Privacy and security support
Ask a question: Email support@allia.health with a security or privacy concern.
Read the privacy policy: View the full policy.
