Mayla Is HIPAA Compliant

Mayla is built for HIPAA-regulated healthcare environments. We sign a Business Associate Agreement (BAA) with every practice before going live, process all patient call data with end-to-end encryption, and integrate exclusively with HIPAA-compliant practice management systems including Dentrix, Eaglesoft, and Jane App.
🔒 BAA included on all plans  ·  US-based data storage  ·  End-to-end encrypted

What's Included

HIPAA Safeguards Built Into Every Plan

Every Mayla customer gets the same compliance foundation — no add-on compliance tier, no enterprise-only security.

📄

Business Associate Agreement

We execute a BAA with every practice before going live — on every plan, including Starter. You receive a fully signed copy for your compliance documentation.

🔐

End-to-End Encryption

All patient call data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Call recordings are stored in HIPAA-compliant US-based infrastructure and accessible only to your practice.

📦

Minimum Necessary Data

We collect and retain only the data needed to complete a booking. We don't store clinical information, insurance details beyond basic eligibility, or any data beyond what's required for appointment management.

🏥

HIPAA-Compliant PMS Integrations

Mayla integrates only with HIPAA-compliant practice management systems: Dentrix, Eaglesoft, Jane App, Open Dental, and Curve Dental. No data passes through non-compliant third parties.

👥

Staff Access Controls

Your Mayla dashboard supports role-based access. You control which team members can access call recordings, review logs, and manage settings. Access can be revoked instantly.

🇺🇸

US-Based Data Storage

All patient call data is stored and processed within the United States. We do not transfer patient data to international servers or use offshore call processing.

For Compliance Officers

Everything You Need to Clear Internal Review

Whether you're a single-location practice or a DSO with a compliance officer on staff, Mayla provides the documentation and controls you need to proceed confidently.

Our BAA is available for review before you sign up. Our security documentation is available on request. Most practices complete compliance review in under a week.

Request Compliance Documentation →
BAA on all plans — not gated behind enterprise tiers
TLS 1.2+ in transit — all call data encrypted during transfer
AES-256 at rest — recordings and booking data encrypted in storage
US-only data residency — no international data transfer
Minimum necessary standard — only booking data retained
Role-based access controls — per-staff dashboard permissions
Audit logging — all data access events logged
Security documentation available on request — for compliance review

Integrates only with HIPAA-compliant systems

Dentrix Eaglesoft Jane App Open Dental Curve Dental

FAQ

HIPAA Questions, Answered

Does Mayla sign a Business Associate Agreement (BAA)?

Yes. Mayla signs a Business Associate Agreement with every practice before going live — on every plan, including Starter. The BAA is executed during onboarding, before any patient call data is processed. You receive a fully executed copy for your compliance records.

Where is patient call data stored?

Patient call data is processed and stored within HIPAA-compliant cloud infrastructure in the United States. Call recordings are encrypted at rest and in transit. We retain only the data necessary for booking and compliance purposes — we do not sell, share, or use patient data for any purpose beyond delivering the Mayla service.

Is it HIPAA compliant to use AI for patient scheduling?

Yes, when the AI vendor signs a BAA and implements appropriate safeguards. The HIPAA Privacy and Security Rules permit the use of AI tools for patient scheduling as long as the vendor is a covered Business Associate with proper data handling controls in place. Mayla meets all of these requirements.

Using an AI receptionist that doesn't sign a BAA would be a HIPAA violation. Always verify BAA status with any vendor handling patient call data.

What HIPAA safeguards does Mayla have in place?

Mayla's HIPAA safeguards include: Business Associate Agreement with every customer; end-to-end encryption on all call data (TLS 1.2+ in transit, AES-256 at rest); minimum necessary data principle (we don't store more than needed for booking); integrations only with HIPAA-compliant PMS systems; role-based staff access controls in the dashboard; US-based data storage; and complete audit logging of all data access.

Can I review your security documentation before signing up?

Yes. Our BAA template is available for review before you commit, and we provide a full security overview document on request. If you have a compliance officer or IT team that needs to review before approval, book a demo and mention it — we'll route you to our compliance contact directly.

What happens to patient data if I cancel Mayla?

When your account is closed, your call recordings and data can be exported or deleted per your instruction. We provide a data deletion confirmation in writing. Our BAA governs data handling through and after termination per HIPAA requirements.

HIPAA-Compliant AI Receptionist, Ready in 48 Hours

Sign a BAA, integrate with your PMS, and go live. No IT project, no compliance risk.