HIPAA
Health Insurance Portability and Accountability Act — Privacy & Security Rules
What Toran does
- • Routes appointment requests, hours / insurance questions, and urgent-case triage to staff WhatsApp.
- • Logs routing metadata only (page URL, time, agent assigned) — not message content.
- • Hands patients off to your HIPAA-compliant portal (Athenahealth, Epic MyChart, etc.) when PHI is needed.
What your clinic still owns
- • Toran is not HIPAA-compliant and we do not sign Business Associate Agreements (BAAs).
- • Train staff to redirect any PHI shared in WhatsApp back to your patient portal rather than responding inline.
- • Use a dedicated tele-health platform (Doxy.me, etc.) for tele-consultation — not Toran or raw WhatsApp.