> ## Documentation Index
> Fetch the complete documentation index at: https://docs.api.dental/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance & Security

> How API Dental protects patient data through HIPAA-compliant architecture, encryption, and a zero-retention data model.

API Dental is purpose-built for dental healthcare data. Patient information is protected at every step — from the moment a request enters our platform to the moment a response is delivered.

## HIPAA Compliance

Our platform is designed to meet HIPAA Privacy Rule, Security Rule, and Breach Notification Rule requirements.

## Zero-Retention Architecture

API Dental is a pass-through gateway. We forward eligibility requests to payer networks and return responses directly to the caller.

* **We do not store patient data.** Eligibility responses are never written to a database.
* **We do not log protected health information.** Patient names, dates of birth, member IDs, and other identifiers are excluded from application logs.
* **We do not build patient profiles.** No historical records, no analytics on patient data, no secondary use of PHI.

There is nothing to breach because there is nothing retained.

## Encryption

All data in transit is protected by TLS 1.2 or higher with 256-bit AES encryption. This applies to every API request, every upstream payer connection, and every response delivered back to the caller.

## Access Controls

Every API request is validated through multiple security checks before reaching payer networks — including authentication, subscription status, payment verification, and rate limiting. Requests that fail any check are rejected before PHI is transmitted.

## Contact

For compliance or security inquiries:

* **Email:** [support@api.dental](mailto:support@api.dental)
