HIPAA & PHI Position
Last updated: July 20, 2026 — Version 1.0
Zero Headache works with healthcare practices, including dental offices, med spas, weight-loss and wellness clinics, and in-home elderly care providers. This page explains how we handle protected health information (PHI) under the U.S. Health Insurance Portability and Accountability Act (HIPAA) and the HIPAA Privacy and Security Rules.
Before you process PHI
Do not route protected health information through the Service until a Business Associate Agreement (BAA) has been signed and a HIPAA-aligned configuration has been enabled on your account. The BAA and the zero-data-retention option are paid add-ons, scoped and priced during your onboarding call. Contact us at contact@zeroheadache.co before your go-live date if you operate in a regulated healthcare vertical.
1. Business Associate Agreement (BAA)
When a healthcare client (a Covered Entity, or a Business Associate acting on one's behalf) uses the Service to handle PHI, Zero Headache acts as a Business Associate. A signed BAA is available to healthcare clients as a paid add-on. The BAA defines our permitted uses of PHI, our safeguards, and our breach-notification obligations under 45 CFR Part 164. Pricing is confirmed during the onboarding call.
2. HIPAA-aligned configuration
A HIPAA-aligned account configuration includes the following. The BAA and zero-data-retention are paid add-ons; pricing is confirmed during the onboarding call. Each item is enabled before the account processes any PHI.
- Encryption of PHI in transit (TLS 1.2 or higher) and at rest (AES-256).
- Zero-data-retention add-on: call audio and transcripts are purged from our systems after they have been synced to your CRM, and no PHI is retained for model training or service improvement.
- Access controls limited to personnel who require access to operate the Service for your account, with audit logging of access.
- Region-pinned hosting for clients who require data residency inside the United States.
- Sub-processors bound by HIPAA-compliant terms where they touch PHI. See the Sub-processor List for the current set.
3. The AI agent does not advise
The AI agent qualifies leads and books appointments strictly within the rules you approve. It never diagnoses, prescribes, or provides medical advice. If a caller asks for medical guidance, the agent routes the call to a human on your team immediately. This boundary is part of the configuration and is not optional.
4. Breach notification
Under the BAA and HIPAA's Breach Notification Rule, we will notify you of any breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery. The notice will include the information required by 45 CFR § 164.410 to allow you to meet your own notification obligations. We provide the information you need to meet your own individual-notification obligations under 45 CFR 164.404, including the individuals affected and the data involved, to the extent available at the time of notice.
5. Data Protection Impact Assessment
We have conducted a Data Protection Impact Assessment covering the processing of call audio, transcripts, and lead data in healthcare contexts. A summary is available to healthcare clients on reasonable request, under NDA.
6. What the Service does not do
We are not a Covered Entity and we do not make treatment decisions. We do not store PHI for our own purposes. We do not use PHI to train, improve, or fine-tune any AI model. We do not sell or share PHI. On termination, PHI is returned or destroyed at your direction, as required by the BAA.
7. Contact
To request a BAA, enable a HIPAA-aligned configuration, or ask questions about PHI handling, contact us at legal@zeroheadache.co. BAA and zero-data-retention pricing is confirmed during the onboarding call.













