HIPAA Posture

Last updated May 27, 2026

This page is maintained by Odify AI (a product of Multy Group LLC) to answer common questions from med-spa, aesthetic, and wellness businesses about how we handle protected health information (PHI). It describes our current practices — it is not a certification or a legal opinion, and it does not by itself create a Business Associate Agreement (BAA).

What Odify does

Odify AI provides an AI phone receptionist and outbound campaign platform. Calls are handled by AI voice agents, transcribed, and stored alongside appointment records synced from your booking platform. We are a service provider — you remain the covered entity (or business associate) for the health information your customers share.

Business Associate Agreement (BAA)

A signed BAA is required before any Odify service handles PHI. BAAs are available on request for eligible customers — contact hello@odify.ai to start the process. Until a BAA is executed, customers should not send PHI to Odify and should configure their AI agents to avoid collecting clinical details on calls.

Safeguards in place

  • Encryption in transit and at rest. All traffic between customers, our services, and our sub-processors uses TLS 1.2+. Data at rest in our managed database and object storage is encrypted with AES-256.
  • Access controls. Customer data is scoped per account and enforced by row-level security. Employees access production systems only through role-based, audit-logged tooling.
  • Audit logging. Sensitive admin and user actions (data exports, deletion requests, permission changes) are recorded to an append-only audit log.
  • Backups & recovery. Managed daily backups are retained by our hosting provider. Odify additionally runs weekly logical dumps of business-critical tables. Restore procedures are documented in an internal runbook.
  • Least-privilege secrets. API tokens for booking platforms and other integrations are stored encrypted in a managed vault and rotated on request.

Sub-processors

Odify relies on a small set of vetted sub-processors to deliver the service, including our hosting/database provider, our AI voice provider (Retell), and our payment processor (Stripe). Under a BAA, Odify will confirm that any sub-processor with access to PHI has an equivalent BAA in place. A current sub-processor list is available on request.

Data retention & deletion

Customers can request a full export of their data or a full deletion at any time from the Settings page. Deletions run on a 30-day soft-delete window so accidental requests can be reversed; after that window, all account-scoped data — including call recordings, transcripts, appointments, and messages — is purged.

Incident response

Security or privacy incidents involving customer data should be reported to security@odify.ai. Under an executed BAA, Odify will notify affected customers of a confirmed breach of unsecured PHI without unreasonable delay and within the timelines the BAA requires.

Shared responsibility

HIPAA compliance is a shared responsibility. Odify secures the platform; customers are responsible for configuring their AI agents, staff access, and booking-platform data in a way that matches their obligations as a covered entity or business associate, including obtaining any patient authorizations required for AI-handled calls.

Questions? Reach us at hello@odify.ai.