HIPAA Compliance Statement
Effective date: August 17, 2026
This statement describes how Cordiva AI protects health information as a Business Associate under HIPAA when providing AI voice receptionist services to medical spas and other clients for whom Cordiva may create, receive, maintain, or transmit Protected Health Information ("PHI").
When Cordiva creates, receives, maintains, or transmits PHI on behalf of a HIPAA-covered entity or other client subject to an applicable BAA, Cordiva acts as a Business Associate and not as a Covered Entity under HIPAA. This statement is not a Notice of Privacy Practices (which is the responsibility of each medical spa).
It describes Cordiva's own compliance program and is not a contract, does not create rights for any individual or client, and does not expand Cordiva's obligations under an applicable Business Associate Agreement ("BAA"), Master Services Agreement ("MSA"), or other written agreement. If there is a conflict, the applicable BAA controls with respect to PHI.
About Cordiva
Cordiva provides AI-powered voice receptionist services to medical spas and other clients in the United States. Cordiva's policy is to treat each Service client as a HIPAA Covered Entity for purposes of the Services and to execute both a Master Services Agreement and a Business Associate Agreement before processing PHI on the Client's behalf. This policy does not constitute a legal determination that a particular Client is, in fact, a Covered Entity under HIPAA. Cordiva AI is based in Madrid, Spain, and operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) when providing these services. We handle Protected Health Information (PHI) on behalf of our clients under executed Master Services Agreements and Business Associate Agreements and only as permitted by the applicable BAA, the client's instructions, and applicable law.
Information We Process
In the course of providing voice receptionist services, we may process the following types of PHI:
- Caller name and phone number
- Appointment requests, confirmations, reschedules, and cancellations
- Questions about specific medical aesthetic services
- Information provided by callers during conversations with our AI receptionist
- Call recordings, transcripts, scheduling information, call metadata, and related Service data, to the extent such information constitutes PHI
How We Use and Disclose PHI
We use PHI only as permitted under HIPAA and our Business Associate Agreement with the medical spa:
- Service delivery: booking and managing appointments, responding to approved service inquiries, providing call-handling functions, and performing related Service activities on behalf of the medical spa, as permitted by the applicable BAA and HIPAA;
- Health care operations and Service operations: operating, securing, maintaining, supporting, troubleshooting, and improving the reliability and quality of the Services using operational telemetry, such as latency, error, completion, success-rate, and sentiment-score data, as permitted by the applicable BAA and HIPAA. Cordiva does not use call recordings or transcripts for routine agent diagnosis or improvement;
- Support and configuration: processing PHI submitted by authorized Client personnel through Cordiva's designated support channel or onboarding and customization chats, where reasonably necessary to support, configure, secure, maintain, or troubleshoot the Services and as permitted by the applicable BAA;
- As required by law: responding to valid legal processes or as otherwise required.
We do not use PHI for marketing purposes. We do not sell PHI.
We do not use PHI to train a general-purpose artificial-intelligence or language model unless the PHI has first been de-identified in accordance with applicable law or another valid legal permission applies. Cordiva may use de-identified information for lawful purposes, including analytics, benchmarking, security, product development, and service improvement, as permitted by the applicable BAA.
How We Protect PHI
Call recordings and transcripts are generally stored by the applicable HIPAA-compliant voice-infrastructure provider and retained for thirty (30) calendar days, subject to the applicable BAA, technical limitations, applicable law, and a different period expressly agreed in writing.
Cordiva uses AWS under a direct BAA to support Client-dashboard delivery, support-ticket content, support-ticket attachments, onboarding and customization chats, and related technical functions. Support-ticket content may be stored in AWS DynamoDB. Support-ticket attachments may be stored in AWS S3 for up to ninety (90) days, with non-current object versions generally purged after seven (7) days, subject to applicable law, backups, security records, and technical limitations.
Cordiva's own systems are designed to minimize persistent storage of call recordings and transcripts. However, PHI may be processed, transmitted, temporarily cached, logged, or transiently retained in Cordiva-controlled systems or authorized Subcontractor systems where reasonably necessary to provide, secure, support, maintain, or troubleshoot the Services.
- All data in transit is encrypted using TLS, where supported by the applicable system or provider
- Access to systems containing PHI is restricted to authorized personnel
- We maintain written policies and procedures for HIPAA compliance
- We conduct regular assessments of our security practices appropriate to the nature and scope of the Services
Cordiva uses administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of PHI, consistent with its role as a Business Associate. No method of transmission, processing, or storage is completely secure, and Cordiva cannot guarantee absolute security.
Our Subprocessors
The following service providers may process PHI on our behalf:
- Retell AI, Inc. — voice call processing, recording, and transcription (BAA signed)
- Amazon Web Services, Inc. — Client-dashboard delivery through AWS Lambda; support-ticket content in DynamoDB; support-ticket attachments in S3; and Amazon Bedrock for onboarding and customization chats (BAA executed)
- Google LLC / Google Workspace — the support@cordiva.ai mailbox, which may receive PHI from authorized Client personnel (BAA executed)
Cordiva accesses language models used for voice interactions through Retell AI and the applicable downstream HIPAA-compliant arrangements. Cordiva uses Amazon Bedrock under its direct BAA with AWS for non-voice product features, including onboarding and customization chats.
Cordiva may also use authorized cloud, telecommunications, security, transcription, messaging, scheduling, and other technical Subcontractors where reasonably necessary to provide the Services. Before permitting a Subcontractor to create, receive, maintain, or transmit PHI on Cordiva's behalf, Cordiva requires a written agreement containing the HIPAA protections applicable to that Subcontractor's role.
A current list of material PHI-handling Subcontractors may be provided to Cordiva clients upon reasonable written request, subject to reasonable protection of confidential, proprietary, and security-sensitive information.
Cordiva's public website contact form is not a PHI-support channel, and visitors should not submit PHI through that form. In contrast, Cordiva's designated support channel is covered by the applicable BAA and may receive PHI from authorized Client personnel where reasonably necessary for support. Client personnel should nevertheless limit such submissions to the minimum information reasonably necessary to describe and resolve the issue. Onboarding and customization chats are covered by the applicable BAA and concern Client business configuration; information submitted in those chats may be incorporated into the applicable agent configuration, scripts, workflows, or other Service settings.
Your Rights
If you are a patient of one of our client medical spas and have questions about how your information is handled during calls with our AI receptionist, please contact your medical spa directly. As a Business Associate, we process PHI on behalf of the medical spa (the Covered Entity), and individual rights requests should be directed to them. Cordiva will assist the applicable medical spa with requests as required by the applicable BAA and HIPAA.
If you have questions specifically about Cordiva's data handling practices, or need to report a security or privacy incident, you may contact us at:
- Security and privacy incidents, and PHI matters: security@cordiva.ai
- Phone: +1 (239) 453-4563
Notices
Cordiva uses email as its primary and sufficient channel for notices. Cordiva does not accept notices by postal mail and designates no postal address for notice purposes.
- Security and privacy incidents, and PHI matters: security@cordiva.ai. A notice to this address is deemed given on transmission, without waiting for the next business day, so that incident and breach-notification timelines run from the moment the report is sent.
- Contractual and legal notices, including termination, breach, non-renewal, and assignment: legal@cordiva.ai. A notice to this address is deemed given on the next business day after transmission, provided the email does not bounce.
- Support and change requests: the in-app support channel or support@cordiva.ai. These are not notices under this section or under any applicable agreement, and a security or privacy incident should never be reported through them alone.
Cordiva gives notices to a client at the email address the client designated in its Order Form or, if the client designated none, at the email address on the client's account. Where a notice is delivered by courier instead of email, it is deemed given on confirmation of delivery. This section describes Cordiva's notice practices; it does not amend the notice provisions of an executed BAA, MSA, or Order Form.
Changes to This Notice
We reserve the right to update this notice at any time to reflect changes in the Services, technology, law, or business practices. The current version will always be available at cordiva.ai/hipaa with an updated effective date. Where required by applicable law, Cordiva may provide additional notice of material changes. Updates to this statement do not amend an executed BAA, MSA, Order Form, or other written agreement unless Cordiva and the client agree to an amendment in writing.
For Medical Spa Owners
If you are a medical spa owner or manager interested in our HIPAA-compliant AI receptionist services, we provide:
- An executed Master Services Agreement and Business Associate Agreement before any PHI is processed.
- Documentation of our security practices and subprocessor agreements.
- Support for your own HIPAA compliance obligations, including implementation support for approved scripts, recording notices, consent workflows, and Service configuration.
Cordiva does not receive or process PHI under any pre-contract trial, evaluation, proof of concept, demonstration, or self-service website subscription. Those are configured and exercised with test data only, and no PHI may be submitted to them. The measured onboarding period that follows go-live is a different thing: it runs under an executed Master Services Agreement and Business Associate Agreement, and Cordiva does process PHI during it.
The only route by which Cordiva processes PHI is a Master Services Agreement ("MSA") and a Business Associate Agreement ("BAA"), both executed by Cordiva and the client. Both agreements must be executed before Cordiva creates, receives, maintains, or transmits any PHI. A BAA executed on its own, without an executed MSA, does not authorize Cordiva to process PHI, and Cordiva will not begin PHI processing on that basis.
The medical spa remains responsible for its own HIPAA compliance program, Notice of Privacy Practices, workforce training, security assessments, patient rights, breach procedures, patient consents, recording and AI-processing disclosures, clinical judgment, emergency procedures, and all other legal and regulatory obligations applicable to its business.
Contact us for a copy of our current MSA and BAA templates.
Contact us at hello@cordiva.ai to learn more.