Security for AI that handles prescriptions.
OneDose agents handle protected health information, so OneDose operates as a business associate: BAAs on every deployment, encryption in transit and at rest, identity verification before any disclosure, minimum-necessary access, and an audit log on every agent action. Clinical decisions route to a human, which is a safety control as much as a product one.
No software is HIPAA compliant by itself. HIPAA regulates organisations and their business associates, not products — so what matters is the agreements and the safeguards around a deployment, not a badge.
What controls apply to a OneDose deployment?
Identity verification before disclosure
The agent establishes who is calling before it says anything about a prescription. Disclosing to the wrong person is a breach regardless of how good the rest of the system is, and the phone is the channel where this is easiest to get wrong.
Encryption in transit and at rest
Including call audio, transcripts and anything derived from them. A transcript of a call about a medication is PHI in exactly the way the call was.
Minimum necessary
The agent accesses and discloses only what the task requires. A caller asking whether a prescription is ready needs "yes, since Tuesday" — not a recitation of their medication history.
An audit log on every agent action
Who accessed what, when, and why. If a breach is ever investigated, the audit log is the evidence — a system that cannot produce one cannot demonstrate compliance even if it was compliant.
A human boundary on clinical decisions
Clinical questions, low-confidence cases and any sign of deterioration route to a person. This is a safety control as much as a product one, and it is the control that keeps the system on the right side of medical-device regulation in several jurisdictions.
What can we evidence today?
Below is each claim with its current evidentiary status, generated from our configuration rather than written by hand — so this list cannot drift ahead of what we can actually produce.
Where an item says Evidence on request, that means exactly what it says: ask and we will provide it. When a report is attached here, it will say Documented and link to it.
- Evidence on request
HIPAA compliant
BAA on every deployment
- Evidence on request
SOC 2 Type II
End-to-end encryption
- Evidence on request
ABDM-ready · ISO 27001
Audit log on every action
- Evidence on request
Regional data residency
IN · US · EU
- Evidence on request
Business Associate Agreements (BAA)
Signed as standard
- Evidence on request
End-to-end encryption
In transit and at rest
- Evidence on request
Full audit logs
On every agent action
A note we would rather write than have you discover: a compliance badge on a vendor page is not evidence, and that includes ours. If you are evaluating OneDose for anything that matters, ask for the report and its scope rather than reading a page — and apply the same standard to every vendor you are comparing us against.
What should you ask us — and every vendor?
These are the questions that separate a real posture from a logo. None of them are unreasonable, and a vendor who resists any of them has told you something useful.
Will you sign a BAA, and can I see it now?
Not "do you support BAAs" — ask for the document during evaluation. It is the fastest possible filter.
Show me the SOC 2 report and its scope.
A logo is not a report. A report covering a different system than the one you are buying is a legal way to display a badge that means nothing to you.
What happens to call audio and transcripts?
Where stored, how long, who can access them, whether they are deleted on request. Retention is where otherwise-reasonable systems quietly fail.
Is our data used to train models — including at your subprocessors?
Get it in writing. A commitment that is not in the agreement is not a commitment.
Which subprocessors touch PHI?
A voice agent is usually several vendors in a trenchcoat — telephony, speech, inference, storage. Each one touching PHI needs to be in the chain of agreements.
Show me the audit log for one call.
An actual example, not a description. The gap between "we log everything" and a usable audit trail is where breach investigations go wrong.
Frequently asked
- Is OneDose HIPAA compliant?
- OneDose is built to be operated under HIPAA: we sign Business Associate Agreements, encrypt data in transit and at rest, verify identity before disclosing anything about a prescription, apply minimum-necessary access, and log every agent action. Strictly, no software is "HIPAA compliant" by itself — HIPAA regulates organisations and their business associates, not products, and there is no HIPAA certification body. Compliance is a property of the deployment and the agreements around it.
- Does OneDose sign a BAA?
- Yes. A OneDose agent handling prescription information processes protected health information on your behalf, which makes us a business associate, which means a BAA. Ask for it during evaluation rather than at contract stage.
- Is OneDose SOC 2 Type II certified?
- Ask us for the report and its scope before relying on this in a procurement process. That is the honest answer and it is also the correct thing to do with any vendor: a badge on a page is not a report, and a SOC 2 covering a different system than the one you are buying is a common and entirely legal way to display a logo that means nothing to you.
- What happens to call recordings and transcripts?
- A transcript of a call about a person’s medication is PHI in exactly the way the call was, and so is anything derived from it. Retention, access and deletion are configured per deployment — ask us for the specifics for your contract, in writing.
- Is our patient data used to train models?
- Ask us directly and get the answer in writing, including whether it covers subprocessors. This is the question most likely to have a comfortable verbal answer and an uncomfortable contractual one, at any vendor — including this one. A commitment that is not in the agreement is not a commitment.
- Where is OneDose data stored?
- Data residency is configured per deployment, and the available regions depend on your contract. Ask us to confirm the residency guarantee for your jurisdiction in writing — residency is a claim that should never be taken from a marketing page in any case, since it is the one a regulator will ask you to evidence.