Skip to content
Home NebulaAI Phone AgentNovaPatient Check-InCoveriCheckInsurance EligibilityEchoAI Medical Scribe Platform overview Demo library Security & compliance About Contact Request a demo
Security & compliance

Handling patient information carefully.

Equinox systems work with protected health information, and that shapes how they're built and how we contract. This page describes our approach. For the specifics your compliance team needs in writing, ask us — we'd rather send documentation than make claims on a marketing page.

Business Associate Agreement

We enter into a BAA with practices before handling protected health information, setting out how PHI may be used, safeguarded and disclosed.

Encryption in transit and at rest

Data moving between your systems and ours is encrypted in transit, and stored data is encrypted at rest.

Least-privilege access

Access to production systems and customer data is limited to the people whose role requires it, and is reviewed.

Audit trails

Actions taken in the platform are logged so your team can reconstruct what happened and when.

Escalation over assumption

When a system can't complete a task confidently — an ambiguous eligibility response, a caller with an unusual request — it flags a person rather than guessing.

Human review where it counts

Clinical documentation and coding suggestions require provider review and approval. Captured documents queue for staff review before chart upload.

Infrastructure

Where Equinox actually runs.

Everything we operate is hosted on major cloud platforms that support HIPAA-eligible workloads under a Business Associate Agreement — not on hardware in a closet.

Hosted on AWS and Microsoft Azure

Equinox systems run on Amazon Web Services and Microsoft Azure. Both offer HIPAA-eligible services and will enter into a Business Associate Agreement covering the services we build on, which is a prerequisite for anything that touches PHI.

Microsoft stays inside your tenant

Where a system works with Microsoft services — the Teams alerts Nova sends when a patient checks in, for example — it operates within your organization's own private Microsoft environment, under your tenant and your administrators' control, rather than in one we run on your behalf.

Azure security enabled before go-live

During onboarding we work through the Azure security configuration with your IT team and confirm the relevant protections are switched on in your tenant before any system goes live.

Because Microsoft runs inside your own environment, your existing identity, access and retention policies apply to it — we don't ask you to route protected health information through a separate workspace we control. Your IT team keeps the administrative rights they already have.

Detail

What to ask us about

Yes. A Business Associate Agreement is executed before we handle protected health information on your behalf. Your counsel is welcome to review it and raise changes.

On AWS and Microsoft Azure, both of which support HIPAA-eligible workloads under a Business Associate Agreement. For your security review we'll put the specifics in writing — which regions, which services, which subprocessors, retention periods and internal access controls — rather than asking you to rely on a summary here.

They run inside your organization's own private Microsoft environment. The alerts Nova sends at check-in are delivered within your tenant, governed by your existing Microsoft agreements, identity controls and retention policies, with your administrators holding the rights they already hold. We don't move that traffic into a workspace we operate. As part of onboarding we go through the Azure security configuration with your IT team and confirm the relevant protections are enabled before go-live.

This is exactly the kind of question that deserves a contractual answer rather than a marketing one. Ask us during your review and we'll put our position and any model-provider terms in writing.

Ask for our current status. We'd rather tell you precisely where we are — including what is in progress and what isn't started — than imply a certification we don't hold.

Incident response and notification obligations are set out in the BAA and service agreement. We'll walk your team through the process before you sign.

A note on this page

Security claims should be verifiable. If anything here matters to your decision, ask for it in writing and hold us to the document rather than the website.

Send us your security questionnaire.

We'd rather work through your review early than discover a blocker after the demo.