Privacy Policy
This Privacy Policy describes how Acucogn LLC DBA Amplit AI ("we," "us," or "our") collects, uses, discloses, and protects your personal and health information when you interact with our front desk AI system, our website at https://www.amplit.ai, and our SMS, voice, and email communications. This policy complies with the Health Insurance Portability and Accountability Act (HIPAA), the Texas Medical Records Privacy Act, and carrier A2P 10DLC messaging requirements.
1. Information We Collect
Personal Information:
- Full name, date of birth, address, email address, and mobile phone number
- Appointment history, scheduling preferences, and front desk interaction notes
Protected Health Information (PHI):
- Information you provide during appointment booking, front desk check-in, or communications with our AI system that relates to your health condition, care, or payment for care
SMS and Voice Data:
- Mobile phone numbers provided by you at the time of booking or contact
- SMS message content, delivery status, and opt-in/opt-out records
- Voice call recordings or transcripts, if applicable and disclosed at the time of the call
Automatically Collected Data:
- IP address, browser type, device information, and website usage data via cookies
2. How We Use Your Information
We use your information for the following purposes:
- Treatment, Payment, and Health Care Operations (TPO): Appointment scheduling, reminders, confirmations, rescheduling, and front desk communications as permitted under HIPAA without separate authorization
- Dentsi / Front Desk AI Operations: Automated call handling, message routing, appointment management, and patient inquiry responses
- Communications: SMS reminders, voice calls, and email notifications related to your appointments
- Minimum Necessary Standard: Our AI system accesses only the PHI strictly necessary for each specific task, in compliance with HIPAA's minimum necessary requirement
3. Text Messaging
If you call a dental practice that uses Dentsi's AI phone assistant to book, reschedule, or manage an appointment, the assistant will ask you directly, by voice, whether you'd like to receive SMS text messages for appointment confirmations and reminders. Your verbal "yes" to that question is your consent; a "no" means we will not text you, and you'll receive confirmations and reminders by email instead. You can change your mind at any time by replying STOP to any text message you receive from us — no further messages will be sent to that number.
Message frequency varies but is typically 1–4 messages per appointment cycle. Message and data rates may apply. No marketing or promotional content is sent via SMS — only messages tied to an appointment you booked.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third party, except that your phone number is shared with Twilio, our SMS delivery provider, strictly for the purpose of delivering messages, under confidentiality agreements.
SMS opt-in and consent records are retained for the duration required by carrier A2P 10DLC requirements.
4. Mobile Information & SMS Privacy
This section governs how we handle mobile information and text messaging data collected through our SMS program (Dentsi Dental Practice Assistant).
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Mobile phone numbers may be shared only with our SMS service provider (Twilio) strictly for the purpose of delivering messages, and only under confidentiality obligations that prohibit the provider from using the data for any other purpose (A2P 10DLC Privacy Policy Requirements; Aircall Compliance).
5. How We Disclose Your Information
- As Permitted or Required by Law: We may use and disclose PHI for treatment, payment, and health care operations without your written authorization, as permitted under HIPAA. We may disclose PHI when required by law, public health reporting, or court order.
- Business Associates: We disclose PHI to our AI vendor and SMS provider only under a signed Business Associate Agreement (BAA) that requires the vendor to safeguard your information and prohibits its use for any purpose other than providing services to us. No PHI is shared with any AI vendor or service provider without a BAA in place before any data is shared (Holland & Hart LLP; Censinet).
- With Your Authorization: We will obtain your written authorization before using or disclosing your PHI for any purpose not described in this policy or permitted by HIPAA, including marketing, sale of your information, or psychotherapy notes.
6. AI-Specific Data Protections
- Approved AI Tools Only: Dentsi and our front desk AI services uses only vendor-approved platforms with a signed BAA. No PHI is entered into consumer-grade AI tools (e.g., public ChatGPT) under any circumstances
- Minimum Necessary Access: Our AI system accesses only the PHI needed for each specific task and is restricted from accessing broader datasets
- De-Identification: Where feasible, data used for AI training or improvement is de-identified using HIPAA Safe Harbor or Expert Determination methods, and re-identification is prohibited
- Audit Logging: All AI interactions involving PHI are logged, including user identity, timestamp, data accessed, and AI output. Logs are retained for a minimum of six years
- Human Oversight: AI-generated content related to clinical matters is reviewed by a qualified staff member before being relied upon or filed in your record
7. Data Security
We implement the following safeguards to protect your information:
- Encryption: AES-256 encryption at rest and TLS 1.3 or higher in transit
- Access Controls: Unique user credentials, role-based access, least-privilege principle, and multi-factor authentication for all systems accessing PHI
- Audit Controls: Logging of all access to PHI, including AI prompt and response records
- Automatic Logoff: Systems accessing PHI enforce automatic logoff after inactivity
- Workforce Training: All workforce members receive HIPAA privacy and security training, including AI-specific data handling guidelines
8. Your Rights Under HIPAA and Texas Law
You have the following rights regarding your PHI:
- Right to Access: You may request a copy of your PHI in electronic or paper form
- Right to Amend: You may request corrections to your PHI
- Right to an Accounting of Disclosures: You may request a list of certain disclosures we have made of your PHI
- Right to Request Restrictions: You may request restrictions on certain uses and disclosures of your PHI
- Right to Confidential Communications: You may request communications by alternative means or at alternative locations
- Right to a Paper Copy of This Notice: You may request a paper copy of this policy at any time
To exercise any of these rights, contact our Privacy Officer at info@amplit.ai or +1 (516) 957-8453.
Texas Medical Records Privacy Act (TMRIA): Under Texas law, you have additional rights including notification of a breach of your unsecured PHI and the right to request electronic copies of your health information. Texas law prohibits the electronic disclosure of your PHI without your separate express authorization, except as permitted by HIPAA.
9. Your Rights Under CCPA/CPRA (If Applicable to California Residents)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CPRA), including the right to know, delete, and correct your personal information, and the right to opt out of the sale or sharing of your personal information. We do not sell your personal information.
10. Breach Notification
In the event of a breach of unsecured PHI, we will notify affected individuals within 60 days of discovery, as required by the HIPAA Breach Notification Rule. Notification will include a description of the breach, the types of information involved, steps you can take to protect yourself, and what we are doing to mitigate the breach. If the breach affects 500 or more individuals, we will also notify the U.S. Department of Health and Human Services and prominent media outlets serving the affected area.
11. Data Retention
We retain your PHI for the period required by law and professional standards, or as necessary for treatment, payment, and health care operations. SMS opt-in and consent records are retained for the duration required by carrier A2P 10DLC requirements. AI interaction logs involving PHI are retained for a minimum of six years.
12. Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect PHI from minors without parental consent. If you believe we have collected information from a minor, please contact our Privacy Officer.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on our website with a revised "Last updated" date. Material changes will be communicated to you via SMS, email, or posted notice at our front desk.
14. Contact Information
Privacy Officer: Anjali Shah (Owner)
Email: info@amplit.ai
Phone: +1 (516) 957-8453
Address: 4100 Spring Valley Rd, Suite 650, Dallas, TX 75244
Website: https://www.amplit.ai
For HIPAA complaints, contact the U.S. Department of Health and Human Services Office for Civil Rights at:
Website: www.hhs.gov/ocr/privacy/hipaa/complaints
Phone: 1-877-696-6775
You will not be retaliated against for filing a complaint.