> ## Documentation Index
> Fetch the complete documentation index at: https://docs.z360.biz/llms.txt
> Use this file to discover all available pages before exploring further.

# What's covered and what's not

> The Z360 services protected under your BAA, and the features that sit outside it.

Your BAA covers a specific set of Z360 services. Everything else is outside it.

## Covered services

In a HIPAA organization, you can use these services with patient information:

| Service | What's covered |
| - | - |
| **Calls and AI voice agents** | Inbound and outbound calls, including calls handled by AI voice agents. AI voice agents identify themselves as AI assistants. |
| **SMS and MMS** | Text and picture messages and those conversations in your Z360 Inbox |
| **Contacts** | Contact records used by your practice as patient information |
| **Call recording, transcription, and AI call summaries** | Call recordings, transcripts, and AI-generated call summaries created from covered calls |
| **Staff dictation** | Dictation used by your team inside covered Z360 workflows |
| **Fax** | Inbound and outbound faxes and the documents they carry |
| **Storage** | The covered data above while it is stored in Z360's encrypted storage in the United States |

To learn how covered data is protected, see [How we handle your data](/hipaa-organizations/data-handling).

## Outside the BAA

Z360 handles features outside the BAA in three ways:

### Not HIPAA-supported and unavailable

These features rely on vendors that do not have the required BAA. They are unavailable for PHI in a HIPAA organization:

* Voices or models labeled **Not HIPAA-supported**.
* Third-party apps connected through the integration service, including calendar connections.

### Outside the BAA

Email, your own EHR or CRM, and custom actions or MCP connections to your own systems are not covered by Z360's BAA by default. After a written request from the BAA signer, a practice-owned destination can be enabled and labeled **Enabled at your request**. Your practice is responsible for the destination's safeguards and can ask Z360 to turn the connection off.

### Configured not to receive PHI

Product analytics and error monitoring are outside the BAA and are configured so they do not receive PHI. Session replay is disabled for HIPAA organizations. Web search and research are blocked for HIPAA organizations and must not be used with PHI.

| Feature | What happens in a HIPAA organization |
| - | - |
| **Email** | Not covered. Your practice is responsible for the mailbox and email provider. See [Email](/hipaa-organizations/shared-responsibility#email). |
| **Third-party integrations** | Not HIPAA-supported and unavailable when the destination does not have the required BAA. |
| **Web search and research** | Blocked for HIPAA organizations. |
| **Product analytics and error monitoring** | Not covered and configured not to receive PHI; session replay is disabled. |
| **Voices and features labeled Not HIPAA-supported** | Unavailable. |

<Note>
  Email appears in the same Z360 Inbox as your texts, but only SMS and MMS conversations are covered. Email isn't.

  Before a covered call is recorded, Z360 plays a recording disclosure that your practice can approve. AI voice agents identify themselves as AI assistants. Your practice is responsible for approving the wording and obtaining any consent required by applicable law.

  HIPAA organizations can turn call recording off and configure automatic deletion where those controls are available in their settings.
</Note>

If you think patient information has gone into a feature that isn't covered, tell us right away at [help@z360.biz](mailto:help@z360.biz).

The covered list can change as we add services. We announce changes in the release changelog, and HIPAA organizations get an email before a change that affects a service they use.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.