HIPAA Notice
Last updated July 1, 2026
There is no such thing as HIPAA certification
We want to be direct about this, because the phrase is common in our category and it is misleading. The US Department of Health and Human Services does not certify anyone as HIPAA compliant. There is no audit, no badge, and no registry. Compliance is a continuing obligation, not a certificate.
So rather than claim a certification that does not exist, this page sets out exactly what we do and what we will put in writing.
Our role
When a covered entity engages Vocryn, we create, receive, maintain, and transmit protected health information on its behalf. That makes us a business associate under HIPAA, and we sign a Business Associate Agreement with every clinic before any patient call is handled.
What the BAA covers
Permitted uses and disclosures of PHI; our obligation to implement administrative, physical, and technical safeguards; our obligation to flow equivalent terms down to subcontractors; breach notification timelines; your right to access, amend, and receive an accounting of disclosures; and the return or destruction of PHI on termination.
Safeguards we implement
Administrative: workforce training, documented policies, least-privilege access reviews, and a designated security contact.
Technical: TLS 1.3 in transit, AES-256 at rest, managed key rotation, role-based access control, single sign-on where available, and complete audit logging of access and configuration changes.
Physical: US-based data centres operated by providers with independently audited physical security controls. No personnel outside the United States have access to PHI.
Minimum necessary
Casey requests only the information needed to complete the administrative task at hand. It does not solicit clinical detail beyond a reason for the call, and it does not attempt clinical triage.
Subprocessors
Delivering voice AI involves downstream processors for cloud hosting, speech recognition, language modelling, and telephony. Each subprocessor that may touch PHI is under a BAA with equivalent obligations. A current list is available on request.
Model training
Your patient data is never used to train shared or third-party AI models. This is a contractual commitment, not a policy statement we can quietly change.
Retention and disposal
Each clinic configures retention for call audio and transcripts, including a zero-retention mode in which audio is discarded at the end of the call and only the structured outcome written to the clinic system is retained. On termination, PHI is returned or destroyed as directed.
Breach notification
We maintain a documented incident-response plan. In the event of a breach of unsecured PHI we notify the affected covered entity without unreasonable delay and within the timeframe set out in the BAA, with the detail required for the clinic to meet its own notification obligations.
What stays your responsibility
Updating your Notice of Privacy Practices to reflect automated call handling; confirming your state’s call-recording consent requirements; including Vocryn in your own security risk analysis and incident-response plan; and configuring Casey’s escalation rules appropriately for your practice.
SOC 2
Our controls are built to SOC 2 Type II criteria. We will share our current security documentation and posture under NDA and tell you plainly where we are in that process. We will not imply a completed audit we do not have.
Requesting documentation
Email care@vocryn.com for the BAA template, data-flow documentation, subprocessor list, and our current security posture. We usually respond the same business day.
Questions
Write to care@vocryn.com or call 1-571-703-4510. For anything a compliance reviewer needs, ask for our security package and we will usually send it the same business day.
This page is provided for information and is not legal advice. Have your own counsel review any agreement before you sign it.
