Watch Algoricum work a live practice in two minutes · See it live →
Security & privacy

Built for healthcare, not bolted on.

Algoricum touches your patients and your records, so consent, privacy, and a check on every message are part of the system, not an afterthought. Here is exactly how your practice and your patients are protected.

The pillars

How your practice and your patients are protected.

Six things that are true on every plan, from your first day.

HIPAA and a BAA

Patient data is handled under HIPAA. We sign a business associate agreement with every practice before any patient data flows.

Encrypted end to end

Your data is encrypted in transit with TLS and at rest, on SOC 2-compliant cloud infrastructure.

Consent built in

TCPA rules, opt-in status, and STOP requests are enforced on every message, before anything is sent.

Least-privilege access

Role-based access and row-level security mean each person sees only what their role allows, and nothing more.

Append-only audit trail

Every decision and message is written to a tamper-evident log that cannot be edited or deleted after the fact.

A human in the loop

New practices start supervised. High-value or low-confidence actions are handed to your team, not sent blind.

The safety layer

Every message is checked before it sends.

Nothing goes out to a patient until it clears three gates. This runs on every text, email, and call, every time.

1

It checks consent first

Before a single word is written, the patient consent and contact status are confirmed. If they opted out or asked to stop, nothing sends.

Gate 1 · consent
  • Do-not-contact and opt-out status respected
  • STOP honored instantly, for good
  • Calling hours enforced for voice, 8am to 9pm local
  • Every message carries an opt-out path
2

Then it checks the message

The content itself is screened before sending, so a patient never gets a broken, misleading, or pushy message in your name.

Gate 2 · content
  • No pressure, scare, or misleading phrasing
  • No unfilled placeholders or broken links
  • Length kept within carrier limits
  • Stays in your approved brand voice
3

Then it sends, and logs it

Only a message that clears both gates goes out, on your own number, and the whole decision is written to the audit trail.

Gate 3 · send and log
  • Sent on your practice number, not a shared one
  • The decision, inputs, and content are recorded
  • The record is append-only and time-stamped
  • Anything unusual is escalated to your team
Your data, your control

It is your data. It stays that way.

We read your records to do the work you hired the agents for, and nothing else.

We never sell or share patient information, to anyone, for any reason.
We do not train models on your patient data.
Encrypted in transit and at rest, with access limited by role.
You can export or delete your data on request.
Messaging runs on your own number and sender identity.
Every access is logged and reviewable by your team.
At a glance

Compliance, in one list.

HIPAA-aligned data handling
Business associate agreement (BAA) with every practice
Encryption in transit (TLS) and at rest
TCPA consent and STOP handling
Role-based access control
Row-level security on every record
Append-only, tamper-evident audit trail
Hosted on SOC 2-compliant infrastructure
No selling or sharing of patient data
No model training on your data
Common questions

Security, answered.

Do you sign a BAA?

Yes. We sign a business associate agreement with every practice before any patient data flows, as HIPAA requires of any partner that handles protected health information.

Where is my data and is it encrypted?

Your data is encrypted in transit with TLS and at rest, and hosted on SOC 2-compliant cloud infrastructure. Access is limited by role, and every access is logged.

Can a message ever go out without consent?

No. Every outbound text, email, and call passes the safety layer first. If a patient has opted out or asked to stop, nothing sends, and STOP is honored the instant it arrives.

Who on my team can see patient data?

Access is role-based and least-privilege, enforced at the database with row-level security. Each person sees only what their role allows, and every view is recorded.

Do you train models on our data?

No. We use your records to do the work for your practice. We never train models on your patient data, and we never sell or share it.

Have a security question? We will answer it.

Book a call and we will walk your team through how Algoricum handles consent, privacy, and your patients’ data.