Security & Compliance
Donna handles sensitive conversations between patients and dental practices. Protecting that data is a design requirement, not an afterthought. This page describes the safeguards that apply to every plan, and the additional controls available with the HIPAA add-on.
Encryption
- All traffic between your callers, our voice infrastructure, and your practice management system is encrypted in transit using TLS.
- Call recordings, transcripts, and booking data are encrypted at rest.
Access controls
- Access to production systems is restricted to authorized personnel on a need-to-know basis, protected by multi-factor authentication.
- Each practice's data is logically separated; your team can only see calls made to your practice.
- Administrative access is logged.
PIPEDA & HIPAA
Canadian practices (PIPEDA). Standard plans are designed to align with PIPEDA: data is stored in Canada, collected with disclosure and consent, used only to deliver the service, and retained only as long as needed. See our Privacy Policy for the details.
US-bound practices (HIPAA add-on). Practices that serve US patients or operate under HIPAA can add our HIPAA compliance package, which includes:
- A signed Business Associate Agreement (BAA)
- PHI-grade encryption standards
- US data residency
- Audit logs suitable for compliance review
Pricing for the HIPAA add-on is available on request.
Incident response
We maintain an incident response process covering detection, containment, and notification. If an incident affects your practice's data, we will notify you without undue delay and cooperate with your own notification obligations.
Data deletion
When you cancel, your call recordings and transcripts are deleted or anonymized after the retention window in your agreement. You may request earlier deletion at any time.
Questions
Security questionnaire or compliance review? Email info@semicolon.oneand we'll get you what you need.