Security and Data Handling

Tivara is built for healthcare environments where every call may contain protected health information. This page describes how we handle PHI, how data moves through our systems, and what clinical operators can expect when they deploy Tivara on their phone lines.

Technical Safeguards

How We Protect Patient Data

We do not sell, license, or use patient call data for model training without explicit written consent. The following controls are standard across all Tivara deployments.

Encryption in Transit and at Rest

All voice data is encrypted with TLS 1.2 or higher in transit. Call recordings and structured call notes stored in our systems use AES-256 encryption at rest. Encryption keys are managed separately from stored data.

Business Associate Agreement

Every clinic that deploys Tivara signs a Business Associate Agreement before going live. This BAA establishes our obligations as a covered entity's business associate under HIPAA and defines permitted uses of PHI.

Data Minimization

Tivara captures only the information necessary to complete a scheduling or refill task. The system does not prompt patients for clinical information beyond what the task requires. Free-form clinical statements are flagged for human review, not stored as structured data.

Automatic Data Retention Limits

Call audio is retained for 90 days by default and then permanently deleted unless your clinic has configured a longer retention period in writing. Structured call notes written to your EMR remain in your EMR system under your data governance policies.

Access Controls

Access to call data is restricted to authenticated clinic administrators and Tivara support staff under role-based permissions. All access events are logged with timestamps, user identity, and the data accessed. Logs are immutable and retained for 12 months.

Infrastructure Hosting

Tivara runs on SOC 2 Type II audited cloud infrastructure within the United States. We do not route call data through data centers outside the US without explicit clinic consent. Subprocessors are listed in our Data Processing Addendum, available upon request.

What We Mean by HIPAA-Addressable

HIPAA compliance is not a certification a vendor obtains and displays. It is a set of ongoing operational and technical obligations shared between a covered entity (your clinic) and its business associates (vendors like Tivara). Our controls are designed to meet the technical and administrative safeguard requirements of the HIPAA Security Rule. We are not a certifying body, and no vendor can make your clinic "HIPAA-compliant" on its own. Deploying Tivara as part of a compliant workflow is a shared responsibility.

We recommend reviewing our BAA with your compliance counsel before deployment. Our implementation team will walk you through the specific configurations required for your state's patient privacy laws in addition to federal requirements.

Data Handling by Call Type

Different call types generate different data. Here is what Tivara captures and routes for each.

  • Appointment scheduling and rescheduling

    Patient name, callback number, appointment type, preferred time, and provider. Written to your EMR scheduling queue via FHIR R4 or direct API.

  • Medication refill requests

    Patient name, date of birth, medication name, pharmacy preference. Routed to your on-call or next-day prescription queue as a structured task. Audio recording retained per your retention settings.

  • Clinical questions and symptom reports

    Tivara does not attempt to answer clinical questions. The caller is told a nurse or care team member will follow up. The call is flagged and escalated. Audio recording is retained; no structured clinical data is extracted from this call type.

  • General inquiries (hours, location, directions)

    No PHI involved. These calls are resolved without data capture beyond call metadata (timestamp, duration, call outcome).

Clinical Safety Protocol

Tivara will not attempt to diagnose, advise, or triage patient symptoms. Any call where the patient describes a symptom, asks about a medication's side effect, or indicates an urgent health concern is immediately escalated. The patient is given an after-hours nurse line or told to call 911 if the call warrants it. This is not configurable. Clinical escalation rules are hardcoded and cannot be turned off by clinic administrators.

Questions About Security?

Our implementation team will walk through any technical or compliance question before you sign anything. Request access and we will follow up with our security documentation package.

Talk to Our Team