How does MiOpsAI protect patient contact information for a family practice?
Patient contact information (name, email, phone, mailing address, insurance carrier name) is treated as sensitive operational data and lives inside your isolated MiOpsAI tenant with per-tenant AES-256 encryption at rest and TLS 1.3 in transit. Even though this data is not PHI, we treat it with the same discipline.
Access controls are role-based: front-desk staff see the operational queue, providers see threads that name them, the practice manager sees everything, and outside vendors see nothing unless you explicitly invite them into a scoped guest role. Every read and write is logged with user, timestamp, and action, so if a question ever comes up about who saw what, the answer is one query away.
Data never crosses tenant boundaries. Other MiOpsAI customers cannot see your patient list, your operational threads, or your reporting. We do not train shared AI models on your data, and LizziAI's drafting draws only from your practice's own patterns.
On the certification side, MiOpsAI is working toward SOC 2 Type II on the 2026 roadmap. Our underlying AWS infrastructure is already SOC 2 Type II certified. HIPAA compliance for the operational surface is not required because we do not touch PHI, but our controls (encryption, access logs, tenant isolation, 2FA, incident response) are built to the standard a HIPAA-covered vendor would need.
The layer we deliberately do not carry is PHI storage or a signed BAA, because forcing PHI through operational tools is the pattern that gets practices in trouble in the first place. Keep PHI in the EHR, keep operational data in MiOpsAI, and the compliance surface stays clean. See the security and compliance FAQ set for the full control list.
Ready to see MiOpsAI in action?
Request access and we’ll walk you through how the platform solves your specific workflow.
Request Access →