Compliance
Kareo practices operate under HIPAA. Our AI receptionist is HIPAA-aware by design: calls are encrypted, PHI stays in your Kareo account, and all interactions are audit-logged.
No extra work: all data handling, encryption, and audit trails are configured for regulated practices by default.
Download call logs, sync history, and access records for any compliance review or audit in seconds.
Patient information stays in Kareo and MedReception only. No third-party databases, no backups on uncontrolled systems.
HIPAA-aware by design
All data handling meets regulatory standards
End-to-end encryption
Calls and PHI protected in transit and at rest
Audit logs on-demand
Full access history for compliance reviews
Business Associate Agreement
BAA in place; MedReception is a Business Associate for Kareo
Yes. MedReception holds a Business Associate Agreement (BAA) and operates as a HIPAA Business Associate. All patient data is encrypted, audit-logged, and retained per your policy.
Yes. All call recordings are encrypted and stored in secure, HIPAA-compliant data centers. You control retention and deletion policies via the MedReception dashboard.
No. The integration uses secure OAuth tokens and API connections. Your Kareo credentials are encrypted and never stored in plaintext. Rotation happens automatically.
Yes. On-demand audit logs show every call, every sync, every API access, and every data modification. Export them in PDF or CSV format for any audit.
All PHI is deleted securely within 30 days of account closure, except data already in your Kareo account, which remains yours. Deletion is logged and auditable.
See how MedReception AI handles after-hours calls, scheduling, intake, and patient communication for medical practices like yours.
Want the numbers first? See plans and pricing