Now onboarding Open Dental practices. Apply for the betaApply
Privacy & Safety · Compliance

Compliance and documentsIn writing, before you sign.

The agreement that governs your patients’ data, the deadlines we hold ourselves to, how each state’s rules are handled, and every document your IT consultant will ask for.

HIPAA and the BAA

One agreement, signed first.

Your practice is the covered entity; we are its business associate. The Business Associate Agreement puts our obligations in writing before any patient data exists.

Signed before any data

No call for your practice is answered and no practice data is touched before your BAA is signed. It comes before the phone line, the PMS connection and the test calls.

One BAA covers every license

A single standard agreement, e-signed, with your choices in an order form. No per-practice variants, and no new agreement when you change license.

Our suppliers, under theirs

Everything that holds your practice’s data runs on AWS under our Business Associate Addendum with AWS, in a United States region.

Our standard BAA is being finalized with counsel. It is signed before any call is answered.Request the BAA

Breach notice

A first notice within 10 calendar days.

Our BAA commits us to tell your practice within 10 calendar days of discovering a breach that affects it. If Florida law sets an earlier date, the earlier date governs.

The outer limits
Our BAA10 days
HIPAA outer limit60 days
  1. Day 0

    Discovery

    We find, or are told of, a breach that affects your practice.

  2. By day 10

    First notice to you

    What happened, what data, what we have done. In writing.

  3. After

    Details as we learn them

    Each update as the facts are confirmed, until the review is closed.

State rules

Recording consent and AI disclosure, state by state.

Recording and AI-disclosure rules differ by state. We switch a state on only after counsel has cleared it, and we will not claim anything we have not checked for yours.

Disclosure on every call

Leady is built to open every call by telling the caller they are speaking to an automated assistant and that the call is transcribed.

Audio waits for counsel

Call audio is off in every state until counsel clears that state's consent rules. No state is cleared today.

States open one at a time

Patient calls start in a state only after our legal review clears it and counsel gives the go-ahead. Florida is first.

AI disclosure, opening line and call audio by state
StateAI disclosureOpening lineCall audio
FloridaEvery callWording being set with counselOff · under legal review
Every other stateEvery callSet with counsel as each state opensOff until cleared

Opening line, every call"You are speaking with Palmetto Bay Family Dental's automated assistant. This call is transcribed."

Illustrative wording. The final line is set with counsel. Sample practice.

Audits

Not SOC 2 certified.

We plan the audit after our first practices go live. No audit date is published until an auditor is engaged.

Not claimed
  1. First

    Our controls, written down

    Each control an auditor would test, with the evidence that shows it works. The ones in place are listed on this page.

  2. Next

    First practices go live

    Onboarding one practice at a time, so controls run on a real system and leave a record.

  3. Then

    The audit

    Planned after our first practices go live. No date is published until an auditor is engaged.

Controls and evidence

What is in place, with the evidence behind it.

Each control below runs today, and each points at a test, a configuration or a recorded read that we can show your reviewer. The ones not yet in place are counted, not described.

Being built34 more being built

Data and privacy

  • Leady staff cannot play call audioIn placeThe database refuses any audio play by a Leady administrator, so only the practice's own authorised staff can listen to a call.
  • No patient data in application logsIn placeCode that handles patient data may not pass it to the application log, and an automated check fails any change that does.
  • No patient data in web addressesIn placePortal addresses use opaque identifiers, so patient details never appear in browser history or request logs.

Infrastructure security

  • Database encrypted at restIn placeThe application database is encrypted at rest and protected against accidental deletion.
  • Verified encryption in transit to the databaseIn placeThe application refuses to connect to a remote database unless the connection is encrypted and the server's certificate is verified.
  • Data hosted in the United StatesIn placeThe application database runs in a United States region.
  • Account activity trailIn placeEvery change to our cloud account is recorded in a tamper-evident trail across all regions.
  • Strong password policy on the cloud accountIn placeCloud account passwords must be at least 14 characters, mixed, and never reused.

Product security

  • Practice data isolationIn placeEvery portal request is scoped to the signed-in practice, so one practice can never read another's data.
  • Invite-only portal accountsIn placeNobody can create a portal account without an invitation from the practice or from Leady.
  • No internal error details in responsesIn placeError responses never return an internal error message, stack trace or raw validation detail to the caller.
  • Double booking refused by the databaseIn placeThe database itself refuses two bookings for the same chair at the same time.

Organizational security

  • Work laptop disk encryptionIn placeThe work laptop's disk is encrypted.
  • Work laptop firewallIn placeThe work laptop's firewall is on and file sharing is off.

Internal security procedures

  • Automated checks on every changeIn placeEvery code change is checked automatically with a typecheck, the full test suite, a build and a secret scan.
  • Booking rules tested against a real databaseIn placeEvery code change runs the booking and data-access tests against a real database, not a mock.

Subprocessors by role

  • Staff sign-inIn placeThe staff sign-in service holds staff identities and roles only, never patient data.

The full list, with what is missing from each control that is not yet in place, is in the security overview.

Subprocessors

Who else touches practice data.

Every supplier we use, what it does for us, what it sees and the agreement we hold with it.

Request the subprocessor list
Suppliers, what each does for Leady, what each sees, and the agreement in place
SupplierWhat it does for usWhat it seesAgreement
AWSHosting, the voice line, the speech model, the database and storagePatient dataPractice and patient dataBusiness Associate Addendum in place
ClerkStaff sign-in to the portalNo patient dataStaff names, work emails and rolesStandard terms
StripeBilling the practiceNo patient dataThe practice's billing detailsStandard terms
HubSpotOur sales recordsNo patient dataProspects who contact usStandard terms
Google WorkspaceCompany email, calendar and documentsNo patient dataNo patient data by designBusiness Associate Agreement in place

A supplier that would handle patient data is added here only after it has signed a Business Associate Agreement with us.

Open Dental is your system, not our supplier: Leady connects to it with your permission, through your own connector.

If this list changes, this page changes with it.

Documents

Everything your reviewer will ask for.

We share the BAA before you sign anything, and the rest on request. Write to security@meetleady.com, or use the form on the overview page.

Incident response

If something goes wrong.

Four steps, written down before we need them. We have never had a security incident, because no practice runs on Leady in production yet.

Being builtRunbook written; put into force before the first practice
  1. 01

    Detect

    A supplier notice, a staff report or a message to security@. Every suspected event goes in an incident log, even when it turns out to be nothing. Automatic alerts are being built.

  2. 02

    Contain Coming

    Stop the exposure first: revoke keys, close access, pause what is affected. An emergency off switch for call handling is being built.

  3. 03

    Notify Coming

    Your practice hears from us within 10 calendar days of discovery, then again as details are confirmed. Written notice templates are being prepared.

  4. 04

    Review

    What happened, why, and what changes. The review is written down and the fix is tracked until it is done.

Responsible disclosure

Found a flaw? Tell us first.

Write to us with what you found, where, and how to reproduce it. Please do not include patient information, and do not access, change or keep data that is not yours. We reply by email.

Security contactsecurity@meetleady.comPrivacy questions: privacy@meetleady.comEmail the security team

Security questions: security@meetleady.com · Privacy questions: privacy@meetleady.com

See all questions

Do you sign a BAA, and when?

Yes, before any call is answered or any practice data is touched. One standard BAA covers every license, with no per-practice variants.

Where is our data hosted?

On AWS, in a United States region, under our Business Associate Addendum with AWS. Every supplier we use is named in the table on this page, with what it sees.

Is data encrypted?

Connections to our database are encrypted and verified, and database storage is encrypted. Encryption rules for stored files are being set up; no files are stored yet.

What do you read from our PMS?

Appointments, chairs, providers, appointment types, and the patient details booking needs. Never clinical notes, imaging, ledgers, payments or payroll.

Do you record calls?

Not today. Audio is off in every state until counsel clears that state. Calls are transcribed, and the caller is told so at the start.

Who at Leady can see our data?

Nobody day to day. When something goes wrong, access goes in logged steps, one call at a time. Nobody at Leady plays call audio: the database refuses it.

How do our staff sign in?

Each person has their own invitation-only account. Today the portal separates administrators from staff; two-step sign-in, per-role settings and the 15-minute idle sign-out are being built.

Do you have a SOC 2 report?

No. We are not certified. We plan the audit after our first practices go live.

Have you had a penetration test?

Not yet. We have not had a third-party penetration test, and we say so until we have.

How quickly will you tell us about a breach?

A first notice within 10 calendar days of discovery, under our BAA, with details added as we learn them.

What happens to our data if we leave?

Calls stop on the termination date. A 30-day transition lets you export your data, and on request we send a copy and delete ours.

Do you use our calls to train AI?

No. Nothing derived from your calls leaves your practice's account, our AWS organization has the AI-services opt-out set, and the optional clause that would let a supplier use our content to improve its services is off.

Keep exploring