Security & Compliance

Patient conversations protected at every step

TensorLinks protects patient information across voice, SMS, web chat, and practice management integrations using administrative, technical, and operational safeguards.

Visit Trust Center
HIPAA CompliantSOC 2 Type 1BAA AvailableAES-256 Encrypted

Last reviewed September 2026 · info@tensorlinks.com

What data is accessed?
Name, contact details, appointment type, and insurance status — only what scheduling requires.
Where is it stored?
US-based infrastructure, AES-256 encrypted at rest. No PHI is transferred overseas.
Who can access it?
Only authorized personnel with a documented business need and annual HIPAA training.
How is it deleted?
Returned or securely destroyed per your BAA upon contract termination.

How TensorLinks protects patient data

Six controls — each designed for healthcare environments.

Data encryption

Patient information is encrypted in transit (TLS 1.3) and at rest (AES-256). Applies to call recordings, messages, and all PMS data.

Role-based access

Team members receive access only for their assigned responsibilities. Permissions are reviewed regularly and revoked immediately on offboarding.

Audit logging

Access, changes, and system events are recorded in tamper-evident audit logs. Available for compliance review upon request.

Minimum necessary access

TensorLinks requests only the information required to complete an approved workflow — scheduling, recall, and communication tasks only.

Secure integrations

Practice management connections use approved authentication (OAuth 2.0, API keys) with restricted read/write permissions scoped to scheduling.

Monitoring & response

Security events are monitored continuously. Confirmed incidents trigger our response procedure with Covered Entity notification within 5 business days.

What happens to patient information

Patient calls
Encrypted connection
Identity checks applied
Approved workflow completed
PMS updated
Action recorded in audit log

A BAA is available for eligible healthcare customers

Before TensorLinks processes Protected Health Information, eligible healthcare customers execute a Business Associate Agreement covering permitted use, safeguards, breach notification timelines, and data handling responsibilities. The BAA is executed at signup — before any PHI flows.

Permitted uses and disclosures of PHI
Administrative, physical, and technical safeguards
Breach notification within 5 business days
Subcontractor flow-down requirements
Data return or destruction upon termination
Sample Document
Business Associate Agreement
Sample only
Read sample BAA text

TensorLinks Inc. — Business Associate Agreement

This Agreement is entered into as of the date of signing between the Covered Entity identified in the associated Services Agreement and TensorLinks Inc., Austin, Texas (“Business Associate”).

Permitted use: Business Associate may use or disclose PHI only as required to fulfil obligations under the Services Agreement, applying the minimum-necessary standard at all times.

Safeguards: Business Associate implements administrative, physical, and technical safeguards (TLS 1.3 in transit · AES-256 at rest · RBAC · MFA · audit logging) in compliance with the HIPAA Security Rule.

Breach notification: Written notice to Covered Entity within five (5) business days of awareness of any unauthorized access, use, or disclosure of PHI.

Subcontractors: Each subcontractor with PHI access is bound by an agreement at least as restrictive as this BAA.

Termination: Upon termination, all PHI is returned or securely destroyed. Where infeasible, protections continue indefinitely.

TensorLinks Inc. · Austin, Texas · Last reviewed September 2026 · privacy@tensorlinks.com

Summary only. Your executed BAA will include complete legal terms. Contact privacy@tensorlinks.com for your signed copy.

Security controls built into every workflow

Four categories of protection, applied at the platform level.

Access
  • Multi-factor authentication
  • Role-based permissions
  • Session timeout controls
  • Automatic account lockout
Protection
  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Encrypted backups
  • Secure data destruction
Monitoring
  • Tamper-evident audit logs
  • Security event alerts
  • Vulnerability scanning
  • 24/7 incident response
Governance
  • Annual HIPAA risk assessments
  • Staff security training
  • Vendor security reviews
  • Subprocessor agreements

Shared responsibility

HIPAA compliance is a shared model. Here is how responsibilities are split.

TensorLinks handles

  • Platform security and encryption
  • System monitoring and alerting
  • Audit logging and retention
  • Incident response and breach notification
  • Subprocessor agreements and oversight

The dental practice handles

  • Authorizing and revoking user access
  • Ensuring accurate user permissions
  • Configuring approved workflows
  • Staff security awareness practices
  • Reporting suspicious activity promptly

General summary only. Have your compliance or legal team review before using for formal risk assessments.

Frequently asked security questions

Have your compliance or IT team review TensorLinks

Access our current security documentation, compliance status, policies, and subprocessor information — all in one place.

info@tensorlinks.com · Security page · Privacy policy