Business Associate Agreement
Ardent is a HIPAA Business Associate and signs a BAA with every practice. The practice is the Covered Entity; Ardent handles PHI only to provide the service the practice has engaged it for.
Security
Ardent reads your schedule, your patients’ insurance details and your payer portals, phones payers on your behalf and files documents into your charts. That is protected health information, and this page says plainly what we do with it. The contractual commitments are in our Terms of Service and Privacy Policy: the BAA, call recording, retention and deletion, and the "results are informational" term. Those documents govern. The operational details below describe how the product works today.
Ardent acts as a HIPAA Business Associate and signs a BAA with every practice; your practice is the Covered Entity. Every subprocessor that touches PHI is under a BAA, and AI extraction runs on a zero-retention endpoint. Data is encrypted in transit and at rest, PHI is kept out of logs, and every PHI access is audit-logged. Results are informational; the practice remains responsible for confirming coverage with the payer.
What we do
Ardent is a HIPAA Business Associate and signs a BAA with every practice. The practice is the Covered Entity; Ardent handles PHI only to provide the service the practice has engaged it for.
Every subprocessor that touches PHI is under a BAA; AI extraction runs on a zero-retention endpoint. The subprocessor list is published in the Privacy Policy.
Encrypted in transit and at rest; PHI kept out of logs. Application logs are written so that patient identifiers, member IDs and benefit details do not appear in them.
Every PHI access is audit-logged: who or what read a patient’s record, and when. Every filed document is a record in Ardent with its trigger, attempt count and outcome.
Hosted in a HIPAA-aligned Google Cloud environment; per-practice tenancy; access limited to staff whose email domain maps to the practice.
Your data stays yours: export for 30 days after you leave, deleted or de-identified within 60; deletion on request.
We do not sell personal information. One httpOnly session cookie, and no advertising or analytics cookies, on the app and on this site.
Ardent writes a PDF into the chart and, where the PMS allows, a note. It never writes coverage-table fields, and its notes go under the office’s own text, never over it. Every automation flag defaults off and is switched on one at a time after a supervised first run.
Payer calls
Calls are recorded, transcribed, and disclosed as recorded on the call. The agent states that the caller is an AI and that the call may be recorded. The recording and transcript are kept with the check: every answer written onto the sheet from a call must be backed by a quote from the rep’s transcript, and a blank the rep did not answer stays blank.
Ardent phones only the payer’s provider line, only inside the payer’s business hours, and only for the required blanks that the portal, EDI or fax left open. Up to two calls per run.
Payer portals
Portal credentials live only for the duration of the call that needs them, and never enter a model, a log line, or a response. Every portal URL is host-allowlisted, so a run for one payer can only reach that payer’s domain. Ardent never solves CAPTCHAs or evades bot protection on payer portals. One attempt per run; if the portal is down, the run retries later rather than pushing.
Emailed one-time codes are read from a mailbox the practice designates for that purpose. SMS and authenticator-app two-factor codes are not supported; for those payers the check moves to the next channel in the playbook, or the run stops and says so.
What a result is
Results are informational; the practice remains responsible for confirming coverage with the payer. Ardent records what the payer said, with its source, onto the practice’s sheet. It does not guarantee coverage or a copay, does not obtain pre-authorizations, and does not replace the practice’s own judgement about a claim. The estimated copay on a CareStack coverage line is an estimate from the payer’s stated rates and the office’s fees.
Full terms: Terms of Service (see "Independent verification; no professional advice") and Privacy Policy. Questions about our security posture: david@ardentdental.co.
Answers
Ardent acts as a HIPAA Business Associate and signs a BAA with every practice. Every subprocessor that touches PHI is under a BAA, AI extraction runs on a zero-retention endpoint, data is encrypted in transit and at rest, PHI is kept out of logs, every PHI access is audit-logged, and data is exportable for 30 days and deleted or de-identified within 60 after an account ends.
Yes, for portal automation. Credentials live only for the duration of the call that needs them and never enter a model, a log line or a response; every portal request is limited to that payer’s domain; emailed one-time codes are read from a mailbox you designate; Ardent never solves CAPTCHAs. Payers without a portal are worked by EDI, fax or phone.
Yes. Calls are recorded, transcribed, and disclosed as recorded on the call; the agent states that the caller is an AI and that the call may be recorded. The transcript is the evidence behind every value a call puts on the sheet, and an answer is accepted only with a quote from the rep behind it.
Staff whose email domain maps to the practice. Each practice is its own tenant; a user at one practice cannot see another’s schedule or charts. Sessions use one httpOnly cookie and nothing else, with no advertising or analytics cookies. Unattended runs act as Ardent itself, which is why the REP blank on a filed sheet reads "Ardent".
Your data stays yours. It is available for export for 30 days after you leave and is deleted or de-identified within 60; deletion on request at any time. The filed sheets already in your charts stay in your PMS; Ardent does not delete documents from the chart.
AI extraction runs on a zero-retention endpoint, and every subprocessor that touches PHI is under a BAA. Portal benefit grids are read through a per-payer field map, not a model; portal credentials never enter a model. What Ardent keeps is the check itself, meaning the sheet, its sources and the audit trail, in its own HIPAA-aligned environment and under your practice’s tenancy.
Ready when you are
A 30-minute demo on your sheet, in your PMS. Bring your breakdown form and we’ll show it filled for a fictional patient.