Skip to main content
No government body issues a software certificate for HIPAA. Z360 offers a signed Business Associate Agreement, safeguards behind it, and evidence of both on request.
If your practice will store or send patient information through Z360, such as calls, texts, contacts, recordings, or faxes, yes. See Get and manage your BAA.
No. Wait for the email confirming that your BAA is active.
Covered data, including calls, texts, contacts, recordings, transcripts, and faxes, is encrypted in transit and at rest.
No. Email is your practice’s responsibility, including your agreement with your email provider and anything sent or received by email. See Email.
Integrations send data to third-party services outside our BAA. In a HIPAA organization, they are turned off so patient information cannot reach them.
These destinations are outside Z360’s BAA by default. The BAA signer at your practice must make a written request to help@z360.biz before the connection is enabled and labeled Enabled at your request. Your practice is responsible for the destination’s safeguards and can ask Z360 to turn it off.
Calendar connections through the third-party integration service are blocked for HIPAA organizations.
Voices labeled Not HIPAA-supported rely on a service outside our BAA, so they are unavailable in HIPAA organizations. HIPAA-supported voices work normally.
Yes. HIPAA organizations can turn call recording off and configure automatic deletion where those controls are available in their settings. Before a covered call is recorded, Z360 plays a recording disclosure that your practice can approve.
No. Z360 does not use your patient information to train or improve AI models, products, or services. See AI and your data.
Email help@z360.biz. Turning it off ends coverage, so Z360 will confirm how you’d like your patient information handled first.
You can export your data for 30 days after the BAA ends. Z360 returns requested data within 30 days, then destroys it under the BAA’s deletion process. See Retention and deletion.
Z360 sends an initial notice within 7 business days after confirming a breach involving your patient information, or sooner when required by state law. A full written report follows within 30 days.
After a valid written deletion request, Z360 deletes patient information from live systems within 30 days and sends written confirmation. Backups may remain on the documented backup schedule.