Built for patient data from the ground up
HIPAA-ready infrastructure, encrypted at rest and in transit, tenant-isolated at the database level.
HIPAA-Ready Infrastructure
ForgeDental is built on infrastructure that meets HIPAA technical safeguard requirements. Business Associate Agreements (BAAs) are available on Professional and Scale tiers.
Encrypted Storage
All patient data — call recordings, SMS threads, PMS-synced records — is encrypted at rest using AES-256. Data in transit uses TLS 1.2 or higher on every connection.
Tenant Isolation
Your practice's data is never mixed with another practice's data at the database level. Every tenant operates in a schema-isolated environment — a query from one practice cannot reach another's records.
What we protect and how
Call Recordings
Every AI-handled call is recorded and stored encrypted. Playback is available through your account portal. Patients hear a recording disclosure at the start of each call. Recordings are retained for 90 days by default (configurable on Scale tier).
PMS Data Handling
We read patient and appointment data from your PMS to enable AI booking and Insights queries. We write back only to the appointment record when the AI books a visit. We do not store clinical notes, chart data, or treatment records.
SMS & Communications
Outbound SMS is handled via a 10DLC-registered number. All message threads are encrypted and tenant-isolated. We process opt-out (STOP) commands automatically and maintain opt-out records per TCPA requirements.
Access Controls
Role-based access at the practice level. ForgeDental engineers do not have routine access to patient records. Staff access to PHI requires documented justification and is logged with a timestamp and user identity.
Business Associate Agreements
BAAs are included with Professional and Scale tiers. If you need a BAA as part of your compliance posture, choose one of those tiers. We'll countersign and return within 2 business days of your onboarding call.
Ask about a BAAVendor compliance
ForgeDental relies on third-party vendors for telephony, SMS, and AI processing. We maintain BAAs with each vendor that handles PHI.
Telephony
HIPAA-eligible voice provider with BAA in place. All call audio handled over encrypted connections.
SMS
10DLC-registered provider. STOP/HELP compliance handled automatically. BAA in place.
AI Processing
LLM inference handled on HIPAA-eligible infrastructure with BAA. Patient identifiers are minimized in prompts wherever possible.
Security questions?
Talk to our team. We'll walk through our security posture, answer your compliance questions, and countersign a BAA if you need one.