Trust Center

Built for practices that cannot afford a HIPAA mistake.

Prefermox answers your patients' calls, so we handle protected health information from the first ring. This page states exactly how that information is protected, what we sign before going live, and what your practice is responsible for.

No call required. The packet includes the security brief, pilot terms, and the full Business Associate Agreement your attorney will want to read.

HIPAA & HITECH Business Associate

Prefermox Operations operates as a Business Associate under HIPAA and the HITECH Act. A Business Associate Agreement is executed before the first live patient call is answered for a practice — never after.

  • Standard ADA/HHS-aligned BAA, available to review before you speak to us
  • 24-hour breach notification commitment
  • Data returned or destroyed at the practice's direction on termination

Encryption in transit and at rest

Every call, API request, and portal session is encrypted end to end. Unencrypted HTTP and SIP connections are rejected outright.

  • TLS 1.3 for portal and API traffic; SRTP for voice media
  • AES-256 encryption at rest for transcripts, recordings, and patient identifiers
  • Practice management credentials stored encrypted, never in plain text

One practice can never see another

Isolation is enforced by the database itself, not by application code that could be bypassed. Every query carries the practice identity of the person making it.

  • Row-level security policies on every table holding patient data
  • Role-based access inside a practice: administrator or front-desk staff
  • Cloud-native portal with zero unencrypted patient data on office workstations

Fail-safe emergency escalation

The receptionist never attempts clinical diagnosis. A suspected emergency is escalated to your designated on-call clinician immediately and redundantly.

  • Live cellular transfer, emergency SMS, authenticated email page, and mobile push
  • Every page acknowledged, re-paged, or resolved with notes by a named person
  • Complete transcript and audio attached to the escalation record

Immutable audit trail

Compliance questions are answered with records, not recollection. Every action leaves a timestamped entry.

  • Calls handled, appointments written, alerts dispatched, transcripts viewed
  • Minimum necessary standard: name, callback number, chief complaint, preferred window
  • Recording disclosure greetings satisfy two-party consent in all 50 states

Availability and continuity

An answering service that goes down is worse than none at all, so the phone path is designed to degrade safely.

  • Redundant, monitored telephony with automatic failover to your front desk line
  • Continuous health monitoring of the voice agent, paging, and schedule sync
  • Call forwarding released back to the practice within one business day of cancellation

What we handle, and what stays with your practice

Prefermox is responsible for
  • Safeguarding PHI created or received while answering your calls
  • Encryption, access control, tenant isolation, and audit logging
  • Written agreements with every subcontractor that touches PHI
  • Breach notification to your practice within 24 hours of discovery
Your practice is responsible for
  • Authorizing call forwarding with your telephone carrier
  • Naming the on-call clinician who receives emergency pages
  • Inviting only staff who should see patient communications
  • Your own Notice of Privacy Practices and workforce training

Security questions, vendor reviews, and DSO due diligence

Send your security questionnaire, IT review, or BAA redlines directly to our compliance contact and you will hear back the same business day.

Steve Benoit · Founder & Principal
steve@prefermox.com
(857) 249-0040

This page describes the controls Prefermox Operations operates today and is not legal advice or a certification. Specific technical and contractual commitments are set out in the Business Associate Agreement and service agreement executed with each practice.