Practical safeguards for PHI-sensitive healthcare operations.

Dexzyle handles communication and documents in HIPAA-regulated workflows. Here is how the platform is actually built — stated plainly, without certification claims we haven't published evidence for.

Your data is protected

Every document, fax, and message is encrypted in transit and at rest. Stored documents are never public — each link is signed and expires, so a forwarded URL does not become a back door. Dexzyle runs on AWS under a signed Business Associate Agreement covering the services that process PHI, and Dexzyle signs a BAA with each customer whose PHI it handles — review our BAA template.

The wrong hands stay out

Every account signs in with multi-factor authentication, so a stolen password alone is not enough, and idle sessions time out on their own. Access is scoped to your organization and its facilities, and each part of the platform — messaging, faxes, documents, provider review, administration — is separately permissioned by role. No one sees more than their role allows.

Records that can’t be quietly rewritten

Fax activity is written to append-only records the application can add to but never modify or delete. User sessions are logged, and AI-assisted features write their own audit entries. When you need to reconstruct who did what — for an incident, a dispute, or a survey — the trail is there, and it has not been edited.

AI assistance stays controlled

AI features are opt-in per organization, with usage quotas and activity logs. They support document summaries and document-grounded questions — they do not make clinical decisions, and they run only in environments covered by our Business Associate Agreement.

Your systems stay yours

Dexzyle integrates with your EHR, pharmacy, and document systems; it does not replace them or claim ownership of the chart. What Dexzyle can read is scoped per organization and confirmed with you during onboarding, and every credential the platform uses is held in a managed secrets vault — never hard-coded or shared.

Questions about our security posture, BAA coverage, or a security review for your organization? Email support@dexzyle.com — we're glad to walk through the details.

Review security with your team

Bring your compliance and IT stakeholders to the demo — integration scope and access controls are part of the walkthrough.