Skip to content
Alvero
Flight DeckCommand CentreDoctors PortalStaff PortalPatient PortalMessengerBookkeeper AIVoice
Economic LayerOperational AgentsMeta-Tier (Learning)Agent LifecycleFull Architecture
DocsFor OwnersCustomersSecurityPricingBlog
Owner LoginBook a Demo
Platform
Flight DeckCommand CentreDoctors PortalStaff PortalPatient PortalMessengerBookkeeper AIVoice
Agents
Economic LayerOperational AgentsMeta-TierAgent Lifecycle
Company
DocsFor OwnersCustomersSecurityPricingBlogAbout
Book a DemoOwner Login

PHIPA / HIPAA Compliance

Last updated: May 31, 2026

Alvero is built for dental practices operating under Canadian provincial health-privacy law (including PHIPA in Ontario and equivalent statutes in other provinces) and, where applicable, the U.S. Health Insurance Portability and Accountability Act ("HIPAA").

Our role

  • In Canada, Alvero acts as an Information Manager / Service Provider to the practice (the Custodian).
  • In the U.S., Alvero acts as a Business Associate to the practice (the Covered Entity), under a Business Associate Agreement ("BAA").

How we operationalize compliance

Tenant isolation

Every practice operates in a dedicated tenant boundary. Row-level security, enforced at the database layer, prevents cross-tenant data access by design — not by policy.

PHI handling

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Access logged at the row level with immutable audit trail.
  • Role-based access control across owner, doctor, staff, and patient roles.
  • Human approval on every outbound PHI event in Messenger — no AI agent may send PHI to a patient without explicit staff sign-off.

Sub-processors

All sub-processors are bound by data-processing terms that flow down PHIPA / HIPAA obligations. Current list available on request.

Staff

Background-checked. Least-privilege production access. Annual privacy and security training.

Incident response

72-hour breach notification commitment to affected Controllers (see DPA §6). Documented incident response plan reviewed annually.

Independent review

Annual third-party security assessment. Next review: Q4 2026.

What we don't do

  • We do not sell or rent any data, ever.
  • We do not train foundation models on identified patient data.
  • We do not use patient data for any purpose outside the Controller's service agreement.

Requesting documentation

  • Executed BAA — [email protected]
  • Sub-processor list — [email protected]
  • Security assessment summary — [email protected]
  • Audit support — [email protected]
This page summarizes our public compliance posture. Detailed security and compliance documentation is shared under NDA with active customers and qualified prospects.
Alvero

Your practice, on autopilot.

owner.alvero.dental  ·  dr.alvero.dental  ·  staff.alvero.dental
Platform
Flight DeckCommand CentreDoctors PortalStaff PortalPatient PortalMessengerBookkeeper AIVoice
Agents
Economic LayerOperationalMeta-TierLifecycleArchitecture
Company
AboutGlossaryCustomersBlogChangelogStatusCareersContact
Legal & Trust
TrustPrivacyTermsDPAPHIPA / HIPAA
© 2026 Alvero, Inc.Built in Kelowna, British ColumbiaLast updated · 31 May 2026