Effective date: September 18, 2026. Operated by Autochrome, Inc., a Delaware corporation (“Autochrome,” “we,” “us”)
Ardent is the insurance verification platform operated by Autochrome, Inc. This policy
is published on ardentdental.co and covers the web application at
app.ardentdental.co and related services. Dental practices use it to verify
patients’ insurance benefits, including by placing outbound calls to payers through
an AI voice agent.
HIPAA note. For protected health information (PHI) we process on behalf of a dental practice, Autochrome acts as a Business Associate and the practice as the Covered Entity. Our handling of that PHI is governed by the Business Associate Agreement (BAA) with each practice, not by this policy. Patients should direct privacy requests about their health information to their dental practice.
To provide and secure the service, place and process verification calls, produce benefit results, support customers, meet legal obligations, and improve reliability. We do not sell personal information.
De-identified data. We create and use de-identified, aggregated data derived from use of the service to operate, analyse, secure, and improve it, and to produce aggregate benchmarks and statistics. De-identification is performed consistent with HIPAA. That data does not identify a practice, a user, or a patient, and we do not disclose it in a way that identifies a practice as its source without that practice’s consent.
Outbound verification calls to payers are recorded and transcribed to produce accurate results and an auditable record. Recording is disclosed on the call, and the practice authorizes it under the Terms of Service. See §6 of the Terms.
We share information only with vendors that support the service. Each vendor that handles PHI does so under a BAA:
We also use Sentry for error monitoring. It is configured to exclude PHI — exception messages, request bodies, and headers are dropped before an event leaves our systems — and it holds no BAA.
We retain a practice’s records for as long as its account is active, so that verification history stays available to the practice.
For thirty days after an account ends, a practice may request an export of its data in a commercially reasonable format. Within sixty days of the account ending, we delete or de-identify that practice’s data in accordance with the BAA, other than copies held in routine backups or retained as required by law. A practice may request deletion at any time, and we honor it promptly. Deletion covers our systems and the recordings and transcripts held by our voice provider.
Encryption in transit (TLS) and at rest, least-privilege access controls, audit logging, and a HIPAA-aligned Google Cloud environment. No method is perfectly secure.
Depending on your jurisdiction (e.g., California CCPA/CPRA), you may have rights to access, correct, or delete personal information and to know retention practices. Requests: david@ardentdental.co. Patient PHI rights are exercised through the dental practice, not this form.
The application sets one cookie: an httpOnly session cookie that keeps you signed in. We use no advertising or analytics cookies. Our marketing site serves its fonts from our own domain, so viewing it sends no request to a third party.
We may update this policy and will post the new effective date.