A defined service boundary
Acuity Health supports administrative patient access and practice operations, including calls, scheduling workflows, staff handoffs, and evidence around completed or unresolved work. Customer-selected integrations vary by deployment.
The service does not diagnose, independently provide clinical triage, prescribe treatment, or replace emergency services. Each medical practice approves its workflows, patient notices, recording and AI disclosures, escalation paths, and clinical boundaries.
Scoped access
Access is designed around the customer security boundary. Authorized users are limited by Practice, permitted Locations, and assigned roles. Access outside those boundaries is not implied by a login or by possession of patient context.
- Practice boundaries separate one customer's workspace from another.
- Location Scope limits Staff access to all or selected Locations as authorized by the Practice.
- Roles distinguish customer responsibilities from Acuity-wide operational access.
- Access Grants are email-bound and revocable. An Access Grant becomes a Membership only when a matching verified User signs in.
Application safeguards
Our current control approach uses explicit technical checks at access, integration, workflow, and delivery boundaries. Operating effectiveness and deployment-specific configuration are validated separately.
- Selected service connections verify requests or require configured credentials before accepting work.
- Credentials and secrets are supplied at runtime rather than committed to application code.
- Typed schemas, input validation, idempotency controls, explicit states, and bounded work protect workflow integrity.
- Selected operational events preserve actor, time, scope, action, and outcome context for support and accountability.
- Version control and automated formatting, linting, type, test, and build checks support controlled software delivery.
Purpose-limited information handling
We seek to use patient information only for the contracted service and authorized workflow. Information made available to a model, integration, employee, or contractor should be limited to what that work requires.
A phone number, name, transcript, or handoff can provide useful context, but it does not by itself establish verified patient identity or become the authoritative medical record. The customer's designated system remains authoritative for the records it owns.
HIPAA and Business Associate Agreements
When Acuity Health handles protected health information as a business associate, an appropriate Business Associate Agreement must govern that relationship. Our control standard also calls for appropriate agreements and technical review before a service provider handles protected health information for an Acuity deployment.
Agreement coverage and technical configuration must be confirmed for the exact products, accounts, services, and customer workflow in use. An executed agreement alone does not prove that every technical or operational control is effective, and this page does not establish HIPAA compliance for a particular deployment.
Risk and incident response
Security is an ongoing operating responsibility. Our process is designed to identify and assess risk, respond to credible security concerns, preserve relevant evidence, remediate confirmed issues, and improve controls after failures.
- Detect and triage a report, alert, or unusual event.
- Contain suspected exposure while preserving evidence needed for assessment.
- Assess scope, impact, affected systems or information, and applicable obligations.
- Notify affected customers as required by the applicable Business Associate Agreement and law.
- Remediate the cause, document the response, and update controls or procedures.
Evidence over assurances
Security claims should be tested against the actual deployment. We maintain supporting agreements, control descriptions, and technical or operational evidence separately for confidential review when appropriate.
Public marketing language cannot replace deployment scoping, legal review, a signed Business Associate Agreement, or evidence that controls are operating as intended.
Start a confidential security review.
Security, privacy, and compliance teams can request the evidence appropriate to a proposed deployment. Supporting materials are shared confidentially and scoped to the services under review.
chase@acuityhealth.io