Security & compliance

What we commit to, in writing

You are letting a vendor touch your schedule and your patients’ contact information. This page is written for the person in your organization whose job is to ask what that means.

Nondiscrimination statement

Funnel Dynamics decides the order and timing of a practice’s outreach. It never decides whether a patient gets care, and it is not used to screen or deny access.

Every patient who contacts a practice using Funnel Dynamics is surfaced to that practice, and every patient is offered an appointment. What the system determines is sequence and timing — who the practice works first, on which channel, and when to follow up with someone who has missed a visit. The practice does the contacting.

The system has no ability to decline an appointment, restrict which services a patient is offered, or remove a patient from a practice’s schedule. Those decisions belong to the practice and its clinicians, and Funnel Dynamics is not in that path.

We support customers conducting Section 1557 nondiscrimination reviews and will answer questions about our processing in writing as part of your review.

Protected health information

  • Funnel Dynamics operates as a business associate under HIPAA and executes a Business Associate Agreement with every practice before any patient data is exchanged.
  • We process the minimum necessary information to prioritize an inquiry and schedule an appointment. We do not request or store clinical notes, diagnoses or treatment records.
  • Patient data is never sold, and it is never used to train models for another customer.

Infrastructure and access

  • Encryption in transit (TLS 1.2 or above) and at rest.
  • Role-based access controls, with production access limited to named personnel and reviewed on a schedule.
  • Comprehensive audit logging of access to patient data, retained and available to you.
  • Environments are segregated by customer; your data is not commingled with another practice’s.
  • Redundant infrastructure across availability zones, automated backups and tested restore procedures.

Certifications and assessments

  • SOC 2 Type II audit in progress. We will share the report and the current bridge letter under NDA on request.
  • Independent security assessment ahead of general availability.
  • Availability and response-time commitments are agreed in your contract rather than published as a marketing figure.

Your practice management system

  • Your PM or EHR system remains the source of truth for the schedule. We read availability and write appointments back.
  • Access is scoped to scheduling and contact data. We do not require broad read access to the clinical record.
  • Access can be revoked by you at any time, from within your own system.

Subprocessors and data location

  • Patient data is processed and stored in the United States.
  • A current list of subprocessors is available on request and before contract signature.
  • We notify customers before adding a subprocessor that handles PHI.

Reviewing us for a security questionnaire?

Ask and we will send the BAA template, the subprocessor list and our current audit status directly.

Privacy policy