Skip to main content
This page covers what Z360 does with patient information in covered services: how we protect it, how AI uses it, how long we keep it, and what happens if something goes wrong.

How we protect your data

  • Encryption in transit and at rest. Patient information is protected while it moves between your practice, your patients, and Z360, and while it is stored.
  • Access controls. Access is limited to people who need it. Your team’s access follows their accounts and roles.
  • Covered subprocessors. Companies that process patient information for covered services are listed in Subprocessors.

AI and your data

Z360 doesn’t use your patient information to build, train, fine-tune, or improve any AI model, product, or service. When a covered service uses an AI model, your data is processed only to deliver that service.
  • Our hosted model service runs inside our cloud environment.
  • Voice AI is provided through a covered voice service.
  • Our speech-to-text provider does not use Z360 patient information for model improvement.
  • Voice-provider observability is disabled for HIPAA call data.
  • The speech-to-text provider receives an opt-out request for each HIPAA transcription or dictation request.
Z360 does not use your patient information to train or improve AI models. Any future use of patient information for a different purpose requires a separate written opt-in.

Retention and deletion

While your BAA is active, we keep your patient information for as long as your practice uses Z360.

Export a patient’s record

An authorized Owner or Admin can export an individual patient’s record from Z360:
  1. Open Contacts and select the patient.
  2. Open the contact actions menu and choose Export Record.
  3. Review the confirmation message, then select Export.
The download includes the patient’s messages, call transcripts, and files. Each export is recorded in the audit trail. Handle the downloaded file like any other patient record. If the record is too large to export in one file, or if your practice needs an organization-wide export, contact help@z360.biz. For a valid written deletion request, Z360 deletes patient information from live systems within 30 days and sends written confirmation. Daily backups may retain data for up to 90 days and monthly backups for up to 365 days. Backups are used for disaster recovery and security only. After the BAA ends, your practice can export data for 30 days. Z360 returns requested data within 30 days and then destroys it under the BAA’s deletion process. Patient access, amendment, and accounting requests are handled within 10 business days when submitted through help@z360.biz.

Security reviews and audits

Z360 provides a yearly security questionnaire and safeguards summary on request at no charge. An audit is available after a security incident or a regulator request, with 30 days’ notice, a confidentiality agreement, and the practice covering reasonable audit costs.

Security incidents

If Z360 confirms a breach involving patient information, we’ll send an initial notice within 7 business days, or sooner when state law requires. We include ransomware and other material security incidents in this process. A full written report follows within 30 days. Your practice decides whether to notify patients, regulators, or the media. If you think patient information has been exposed or sent to a feature that isn’t covered, email help@z360.biz right away.