Skip to main content
Missed Calls Dental
Overview Watch sample call Call the live demo
Pricing Blog
FAQ Help Center ↗
Sign in Start trial

HIPAA

Last updated: August 19, 2026

Missed Calls Dental operates a HIPAA compliance program to protect PHI handled on behalf of dental practices.

On this page
  • Overview
  • BAA
  • Safeguards
  • Data protection
  • Access controls
  • Incident response and recovery
  • Retention and deletion
  • Clinic responsibilities

Overview

Missed Calls Dental, a service of AllyExporter LLC, protects Protected Health Information (PHI) that it creates, receives, maintains, or transmits for participating dental practices. We maintain administrative, physical, and technical safeguards and operate policies and procedures designed to meet the applicable requirements of the HIPAA Privacy, Security, and Breach Notification Rules.

Our role under HIPAA

When Missed Calls Dental handles PHI to provide the service for a dental practice, AllyExporter LLC acts as the practice’s Business Associate. We use and disclose PHI only as permitted by the applicable Business Associate Agreement, to provide the service, or as required by law. We apply the minimum necessary standard to access, use, and disclosure.

BAA

We enter into a Business Associate Agreement (BAA) with covered entity customers. The BAA defines permitted uses and disclosures, safeguards, incident and breach duties, subcontractor obligations, access and amendment support, accounting of disclosures, termination, and return or destruction of PHI.

Before Missed Calls Dental creates, receives, maintains, or transmits PHI for a practice, the account Owner executes the BAA. The Owner can review, sign, and download it in Legal & HIPAA in the clinic account.

Safeguards

Administrative safeguards

Our security program includes documented risk analysis and risk management, assigned security responsibility, workforce authorization and training, access review, incident procedures, contingency planning, vendor oversight, and periodic evaluation.

Physical safeguards

We restrict physical access to facilities, workstations, devices, and media used to administer the service. Device and media procedures address authorized use, storage, disposal, reuse, loss, and removal.

Technical safeguards

We use unique identities, authentication, role-based authorization, audit controls, integrity protections, session controls, and transmission security. ePHI stored by the Service is encrypted at rest, and electronic transmissions under our control are protected in transit using appropriate cryptographic controls.

Data protection

PHI is used only for defined service and legal purposes. Public website, marketing, payment, and public Help Center workflows are not approved channels for PHI. Providers may handle PHI only when necessary for an approved service, within the applicable contractual HIPAA scope, and subject to required written protections.

Access controls

Access is limited by job responsibility, least privilege, and minimum necessary. Production access requires authorization, strong authentication, and multi-factor authentication for privileged access. Access is logged, reviewed, and removed when no longer required. Each clinic controls its own users and permissions.

Incident response and recovery

Documented procedures cover detection, triage, containment, investigation, evidence preservation, mitigation, recovery, breach assessment, notification, corrective action, and lessons learned. Security Incidents and potential breaches involving customer PHI are handled and reported in accordance with the BAA and applicable law.

Contingency procedures address protected backups, restoration, disaster recovery, emergency operations, dependency failures, and return to normal service. Recovery procedures and backups are tested and findings are tracked to completion.

Retention and deletion

We retain information only for defined service, security, contractual, accounting, or legal purposes. Canceling a subscription does not itself delete account data or terminate the BAA while we continue to maintain PHI. When the account is closed and the service relationship ends, PHI is returned or destroyed when feasible. The BAA and its protections remain in effect for retained PHI. If return or destruction is infeasible, the PHI remains protected and further use or disclosure is limited to the reason preventing return or destruction. Residual backup copies remain protected and expire through the scheduled backup lifecycle.

Clinic responsibilities

Each clinic is responsible for authorizing its users, assigning appropriate access, protecting credentials and devices, providing required patient notices, obtaining required consents, and using the service in accordance with law, the BAA, and clinic policies. Missed Calls Dental does not provide medical advice, diagnosis, treatment recommendations, or emergency guidance.

Related policies

For additional information, review our Privacy Policy and Terms of Service.

© 2026 Missed Calls Dental
BlogPartner Program HIPAA Privacy Policy Terms of Service SMS Terms Contact Help Center