Skip to main content
Acuity Health

Public security posture

Security, privacy, and HIPAA at Acuity Health.

Acuity Health is operated by Data Buddies Solutions LLC. We design our patient-access services to protect information through explicit access boundaries, validated workflows, operational evidence, and shared responsibility with each medical practice.

Data Buddies Solutions LLC d/b/a Acuity HealthLast updated

A defined service boundary

Acuity Health supports administrative patient access and practice operations, including calls, scheduling workflows, staff handoffs, and evidence around completed or unresolved work. Customer-selected integrations vary by deployment.

The service does not diagnose, independently provide clinical triage, prescribe treatment, or replace emergency services. Each medical practice approves its workflows, patient notices, recording and AI disclosures, escalation paths, and clinical boundaries.

Scoped access

Access is designed around the customer security boundary. Authorized users are limited by Practice, permitted Locations, and assigned roles. Access outside those boundaries is not implied by a login or by possession of patient context.

  • Practice boundaries separate one customer's workspace from another.
  • Location Scope limits Staff access to all or selected Locations as authorized by the Practice.
  • Roles distinguish customer responsibilities from Acuity-wide operational access.
  • Access Grants are email-bound and revocable. An Access Grant becomes a Membership only when a matching verified User signs in.

Application safeguards

Our current control approach uses explicit technical checks at access, integration, workflow, and delivery boundaries. Operating effectiveness and deployment-specific configuration are validated separately.

  • Selected service connections verify requests or require configured credentials before accepting work.
  • Credentials and secrets are supplied at runtime rather than committed to application code.
  • Typed schemas, input validation, idempotency controls, explicit states, and bounded work protect workflow integrity.
  • Selected operational events preserve actor, time, scope, action, and outcome context for support and accountability.
  • Version control and automated formatting, linting, type, test, and build checks support controlled software delivery.

Purpose-limited information handling

We seek to use patient information only for the contracted service and authorized workflow. Information made available to a model, integration, employee, or contractor should be limited to what that work requires.

A phone number, name, transcript, or handoff can provide useful context, but it does not by itself establish verified patient identity or become the authoritative medical record. The customer's designated system remains authoritative for the records it owns.

HIPAA and Business Associate Agreements

When Acuity Health handles protected health information as a business associate, an appropriate Business Associate Agreement must govern that relationship. Our control standard also calls for appropriate agreements and technical review before a service provider handles protected health information for an Acuity deployment.

Agreement coverage and technical configuration must be confirmed for the exact products, accounts, services, and customer workflow in use. An executed agreement alone does not prove that every technical or operational control is effective, and this page does not establish HIPAA compliance for a particular deployment.

Risk and incident response

Security is an ongoing operating responsibility. Our process is designed to identify and assess risk, respond to credible security concerns, preserve relevant evidence, remediate confirmed issues, and improve controls after failures.

  • Detect and triage a report, alert, or unusual event.
  • Contain suspected exposure while preserving evidence needed for assessment.
  • Assess scope, impact, affected systems or information, and applicable obligations.
  • Notify affected customers as required by the applicable Business Associate Agreement and law.
  • Remediate the cause, document the response, and update controls or procedures.

Shared responsibility

A secure deployment depends on both Acuity Health and the medical practice. The customer controls its users, endpoints, networks, systems of record, workflow approvals, patient notices, and escalation policies. Acuity controls the service components and responsibilities assigned to it by the customer agreement.

  • Acuity restricts authorized service access, protects its managed credentials, enforces configured workflows, and responds to incidents within its scope.
  • The medical practice authorizes users, removes access promptly, approves workflows and disclosures, and maintains its own endpoint and record-system controls.
  • Both parties should report suspected misuse or compromise promptly and keep deployment decisions documented.

Evidence over assurances

Security claims should be tested against the actual deployment. We maintain supporting agreements, control descriptions, and technical or operational evidence separately for confidential review when appropriate.

Public marketing language cannot replace deployment scoping, legal review, a signed Business Associate Agreement, or evidence that controls are operating as intended.

Start a confidential security review.

Security, privacy, and compliance teams can request the evidence appropriate to a proposed deployment. Supporting materials are shared confidentially and scoped to the services under review.

chase@acuityhealth.io