Roottine collects and acts on patient contact information and appointment history, and its AI assistant sits inside a healthcare context. Here is exactly how that\'s handled — not retrofitted after the fact, but built in from the start.
Data moving between your practice, your patients, and Roottine is encrypted in transit. Data at rest in our database is encrypted using our infrastructure provider's standard encryption.
Patient records, messages, and dashboard data are scoped to the practice that owns them at the database level. No practice can see another practice's patient data, ever.
Team members you invite only see what their role requires. Access to patient records, billing, and settings is controlled per account, not shared through a single generic login.
Any system with access to patient contact and visit information is treated as a HIPAA business associate. We provide a signed Business Associate Agreement to practices that request one.
This is enforced in the assistant's code, not just in its instructions. Anything resembling a symptom, a diagnosis question, or medication advice is refused and routed to "please call the practice" — every time, with no exceptions.
Every automated message, gift, and AI-assistant answer is scoped to what the practice itself configured or uploaded. Nothing is invented or pulled from outside the practice's own information.
The clearest, most consistently documented compliance risk for a healthcare-adjacent chatbot is scope creep into clinical territory — a chatbot that starts confidently answering a symptom question is functioning as an unlicensed clinical intermediary, regardless of intent. Routing every clinical question to "please call us" isn't a UX preference in Roottine; it's the primary compliance control for the entire AI Assistant feature, enforced in engineering, not just in prompt wording.
Liability for anything that resembles clinical guidance, even AI-generated, sits with the practice and its licensed dentist — not with Roottine as the software vendor. We are explicit with practices during onboarding about what the assistant will and won't do, so it's never mistakenly represented to patients as more clinically capable than it is.
Roottine does not store diagnoses, treatment notes, clinical images, or procedure codes. The data we hold is limited to what the recall, milestone, nurture, and loyalty systems actually need: contact details, appointment/visit dates, and engagement history within the app.
Reach out directly and we'll answer it, or connect you with the details your practice's compliance officer needs.
Contact us