How Nutaan protects patient information
Each of these is part of the product today — not a roadmap.
Patient details masked by default
Phone numbers and emails are masked for every login. Only the account owner can reveal one, one record at a time; team members never see the real number — they call through a relay that keeps it hidden.
Role-based access
Owner and team-member roles, and API keys limited to the permissions they need — a key that can read calls cannot place them.
Audited support access
When Nutaan support opens an account to help, the session is recorded in an audit trail first; if the record cannot be written, no access is granted.
Encrypted in transit, hosted on Azure
All traffic is encrypted with TLS. The platform runs on Microsoft Azure; integration credentials and tokens are stored encrypted.
Permanent deletion
Deleting an account removes its data — including agents and knowledge stored with our voice infrastructure — not just the login.
Clinical safety built into agents
Agents escalate emergencies to the right number immediately, verify identity before sharing details, never give clinical advice, and route refills and clinical questions to your staff.
A BAA, on request
Under HIPAA, a vendor that handles protected health information for you is a business associate and signs a BAA. Nutaan signs one with healthcare customers before patient calls go live.
There is no official HIPAA certification for software vendors. What a practice needs is a vendor that applies the safeguards and signs a BAA — and its own policies for the rest.
Watch Nutaan answer patient calls
Replace IVR Bots with AI Calling
Why press-1 phone menus lose callers, and how a Nutaan AI agent answers in conversation instead.
Meet Nutaan AI — an AI employee that works 24/7
Nutaan handles everyday business operations — calls, qualification and follow-up — around the clock.
HIPAA questions, answered
Is Nutaan HIPAA compliant?
Nutaan is built for HIPAA and offers a Business Associate Agreement (BAA) to healthcare customers on request. HIPAA compliance is shared: Nutaan provides the safeguards and signs the BAA; your practice configures access and follows its own HIPAA policies. There is no official "HIPAA certification" for any vendor.
Will Nutaan sign a BAA?
Yes. A Business Associate Agreement is available for healthcare customers — ask for it when you book a demo or before you go live with patient calls.
Who can see a patient’s phone number?
Numbers and emails are masked for every login. Only the account owner can reveal a number, one record at a time. Team members never receive the real number; calls to patients go through a relay that keeps it hidden.
Does the AI give medical advice?
No. Agents handle scheduling, reminders, intake and refill requests, verify identity before sharing details, route clinical questions to your staff, and direct emergencies to emergency services immediately.
Where is data hosted?
The platform runs on Microsoft Azure, with all traffic encrypted in transit (TLS).
Can we delete patient data?
Yes. Deleting an account permanently removes its data, including agents and knowledge stored with our voice infrastructure.
Explore AI calling for healthcare, primary care and Epic integration.
