If you run a dental practice, vet clinic, or med spa, you've probably noticed that most scheduling software wants to integrate with your PMS (Dentrix, Open Dental, Eaglesoft, Aesthetic Record). The moment it does, you're inside HIPAA scope — BAAs, audit logs, breach reporting, the whole apparatus. Deskwise takes a different approach: we never touch PHI, so we stay outside HIPAA scope entirely. This page explains what that means in practice.
What counts as PHI
PHI (Protected Health Information) is patient identifier + medical fact. Specifically:
- Diagnoses ("diabetes," "hypertension," "cavity on tooth #14")
- Treatment plans + chart notes
- Prescription names + dosages
- Insurance member IDs + claim details
- Radiology images + lab results
- Anything that ties a person to a medical condition
What's NOT PHI: name, phone, email, appointment time, service type ("cleaning," "botox touch-up"). That's scheduling data — business contact + calendar, not medical record. Deskwise operates entirely in this layer.
What the agent will not do in healthcare verticals
- Discuss symptoms ("my tooth has been hurting")
- Discuss medications ("can I take ibuprofen with my Lexapro?")
- Take insurance information (member IDs, group numbers, plan details)
- Confirm or discuss any clinical content ("is the abscess healed?")
- Echo medical information back even if the client volunteers it
- Log medical content to the conversation database
When a client mentions any of the above, the agent redirects: "I'm here for scheduling — please discuss that with Dr. [Name] at your visit." A redaction layer runs on the conversation before storage, stripping anything that looks like a medical record number, prescription name, ICD code, or insurance pattern.
What the agent does handle
- Booking by procedure type (cleaning, exam, consultation, IV drip)
- Routing to the right provider based on procedure
- Recall outreach for 6-month cleanings, annual exams, vaccine boosters
- Reschedule + cancellation logic
- Deposits + no-show fees (zero PHI involved)
- Handoff to your existing intake forms (text the client a link, don't capture the answers ourselves)
- Dormant patient recovery (the highest-ROI flow in healthcare scheduling)
Why we don't integrate with your PMS for clinical data
Some vendors would say "we'll integrate with Dentrix and pull charts so the agent knows the patient." That's a HIPAA-business-associate relationship and requires a BAA + audit program. It also means a single breach in our infrastructure could expose every client's chart across our customer base. We chose to design out of this exposure entirely — your PMS holds clinical records, Deskwise holds scheduling. Two systems, two scopes.
We do support write-back webhooks (a booking made via Deskwise can be pushed to your PMS calendar) so you don't have double-entry. But Deskwise never reads clinical data from the PMS.
Compliance posture summary
- Data we collect: name, phone/email, appointment history with you, service preferences, payment method
- Data we do not collect: anything in the PHI list above
- Encryption: TLS in transit, AES-256 at rest, standard for SaaS
- Access control: role-based, audit-logged
- Data residency: US (AWS us-east + Cloudflare)
- Sub-processors: Stripe, Twilio, Vapi (voice), Anthropic (Claude), Vercel (hosting)
- Deletion: full account deletion within 30 days of request
Frequently asked
Can I get a BAA from Deskwise?
No — and that's the point. We don't sign BAAs because we don't handle PHI. Signing one would imply we do, which would create legal ambiguity. If you need a BAA-signed scheduler, you'd want a HIPAA-scoped vendor (and accept the compliance overhead that comes with it).
What if a client texts me a photo of a rash?
The agent declines to engage. The image is held in the conversation but isn't analyzed or echoed. You can choose to set a policy where image messages auto-escalate to a human.
Is dental scheduling without PHI actually compliant?
Yes. Many independent dental practices use phone-based front desks, paper sign-in sheets, and standalone scheduling — none of which trigger HIPAA. Deskwise is the digital equivalent: same scope, same compliance posture. We've had this reviewed by healthcare-compliance counsel.
Related in Healthcare
Didn’t answer your question?
Email contact@deskwise.coand we’ll get back within 4 business hours. Or book a 15-min call.