Security & privacy, in plain language
Your practice is handing us patient information. Here is how we treat it — and where the full documents are.
Two roles, kept separate
For patient information, we are a service provider to your practice: the practice owns the records and decides what happens to them; we process them only to run the tools you switched on. For information about our own customers, prospects and website visitors — your name and email, your subscription — we are the party responsible. The Privacy Policy is written around that distinction, and so is everything below.
The Business Associate Agreement
We operate as a HIPAA business associate to your practice. The BAA is part of the terms you accept when you create your account — it applies automatically, with no separate signature — and commits us to safeguards under the HIPAA Security Rule.
If a breach ever affects your patients' information, we notify you within thirty days — stricter than the sixty HIPAA allows.
How the data is protected
Encryption in transit and at rest. Least-privilege access controls. Individually credentialed user accounts for every person on your team. Network and application-level safeguards, with monitoring.
Hosted in the United States on Amazon Web Services.
Who else touches the data
Only the companies that run a piece of the service for us — hosting and email on AWS, payments through Stripe, text messages through Twilio, posting to your own Facebook and Instagram through Meta, and analytics on the business side through Google. Each one, what it handles and whether it can see patient information is listed, and the list is kept current.
What we don't do
We do not sell information. We do not use your data to train AI models. We run no analytics or advertising trackers on the patient membership portal, and no advertising cookies or retargeting pixels anywhere.
Your data stays yours
If you stop using the tools, you keep read-only access to everything they recorded — nothing disappears at the end of the free period or after a cancellation. If you want it deleted, you ask, and we delete it; the Data Deletion instructions say exactly how, for practices, patients, prospects and affiliates.
Patients' rights over their health information run through the practice, as HIPAA intends: a patient who wants to see, correct or delete treatment information asks their dentist. Text messages stop the moment a patient replies STOP.
Data Deletion instructions · Master Subscription Agreement · The whole Legal Center
A question we can't answer here?
Security questionnaires, your compliance officer's questions, anything specific to your practice — email support@profitsmiles.com and we will answer in writing.
Try it with your own data — it stays yours either way.
Free for a hundred days, every tool, no credit card.
Start the 100 Day Protocol FreeFree for 100 days · No credit card · Your data stays yours