> ## Documentation Index
> Fetch the complete documentation index at: https://docs.z360.biz/llms.txt
> Use this file to discover all available pages before exploring further.

# HIPAA FAQ

> Common questions from healthcare practices about HIPAA on Z360.

<AccordionGroup>
  <Accordion title="Does Z360 have a HIPAA certificate?">
    No government body issues a software certificate for HIPAA. Z360 offers a signed Business Associate Agreement, safeguards behind it, and evidence of both on request.
  </Accordion>

  <Accordion title="Does my practice need a BAA with Z360?">
    If your practice will store or send patient information through Z360, such as calls, texts, contacts, recordings, or faxes, yes. See [Get and manage your BAA](/hipaa-organizations/get-a-baa).
  </Accordion>

  <Accordion title="Can we use Z360 with patient information before the BAA is active?">
    No. Wait for the email confirming that your BAA is active.
  </Accordion>

  <Accordion title="Is our data encrypted?">
    Covered data, including calls, texts, contacts, recordings, transcripts, and faxes, is encrypted in transit and at rest.
  </Accordion>

  <Accordion title="Is email covered by our BAA?">
    No. Email is your practice's responsibility, including your agreement with your email provider and anything sent or received by email. See [Email](/hipaa-organizations/shared-responsibility#email).
  </Accordion>

  <Accordion title="Why are integrations turned off?">
    Integrations send data to third-party services outside our BAA. In a HIPAA organization, they are turned off so patient information cannot reach them.
  </Accordion>

  <Accordion title="Can we connect our own EHR, CRM, or mailbox?">
    These destinations are outside Z360's BAA by default. The BAA signer at your practice must make a written request to [help@z360.biz](mailto:help@z360.biz) before the connection is enabled and labeled **Enabled at your request**. Your practice is responsible for the destination's safeguards and can ask Z360 to turn it off.
  </Accordion>

  <Accordion title="Are calendar connections available in a HIPAA organization?">
    Calendar connections through the third-party integration service are blocked for HIPAA organizations.
  </Accordion>

  <Accordion title="Why are some voices unavailable?">
    Voices labeled **Not HIPAA-supported** rely on a service outside our BAA, so they are unavailable in HIPAA organizations. HIPAA-supported voices work normally.
  </Accordion>

  <Accordion title="Can we control call recording?">
    Yes. HIPAA organizations can turn call recording off and configure automatic deletion where those controls are available in their settings. Before a covered call is recorded, Z360 plays a recording disclosure that your practice can approve.
  </Accordion>

  <Accordion title="Do you use our data to train AI?">
    No. Z360 does not use your patient information to train or improve AI models, products, or services. See [AI and your data](/hipaa-organizations/data-handling#ai-and-your-data).
  </Accordion>

  <Accordion title="Can we turn off BAA mode?">
    Email [help@z360.biz](mailto:help@z360.biz). Turning it off ends coverage, so Z360 will confirm how you'd like your patient information handled first.
  </Accordion>

  <Accordion title="What happens to our data if we leave Z360?">
    You can export your data for 30 days after the BAA ends. Z360 returns requested data within 30 days, then destroys it under the BAA's deletion process. See [Retention and deletion](/hipaa-organizations/data-handling#retention-and-deletion).
  </Accordion>

  <Accordion title="How quickly will Z360 tell us about a security incident?">
    Z360 sends an initial notice within 7 business days after confirming a breach involving your patient information, or sooner when required by state law. A full written report follows within 30 days.
  </Accordion>

  <Accordion title="How quickly does Z360 delete patient information?">
    After a valid written deletion request, Z360 deletes patient information from live systems within 30 days and sends written confirmation. Backups may remain on the documented backup schedule.
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.