Skip to content

Security, privacy & governance

Controls for your
patient access process.

Set who can access your workspace, which actions Korenact can take and when staff approval is required. Your facility must review the hosting, data handling and service agreements before going live.

Plan a healthcare pilot

Controls in the product

What the product
can control today.

01

Access controls

Users sign in to their organization’s workspace. Their roles determine whether they can change settings, handle live conversations or approve actions.

02

Organization permissions

Choose the information a workflow can use and the actions it can take. An action cannot run without the required permission.

03

Data protection

Appointment lookups and changes require verified contact details. Verification answers are masked in saved conversations and kept out of optional language processing.

04

Audit history

Staff can review recorded permissions, approvals and action results, including failures and uncertain outcomes.

05

Action approvals

Rules are checked before an action runs. When staff approval is required, Korenact checks it again before proceeding.

06

Staff review

Requests that need attention go to your staff queue with the allowed conversation details. Your team monitors the queue and decides when to respond.

07

Integration security

Scheduling connections use authorized accounts. Credentials stay on the server; administrators manage only the approved connection settings in the workspace.

08

Retention controls

You can record a conversation retention target. Automatic deletion does not cover all records, so your deployment still needs an enforced retention process.

09

Private deployment options

If you want to host on your own infrastructure, review the access, storage, recovery and service agreements that setup needs.

10

Operational monitoring

Review conversation results and connection health. Failed or uncertain actions are recorded separately from confirmed changes.

Operating your deployment

Assign the people
responsible for the setup.

Product controls are part of the setup. Your team also needs to manage user access, connected services and staff follow-up.

Read the privacy policy

Infrastructure & access

Your deployment operator is responsible for secure connections, storage protection, backups, credential rotation and infrastructure access.

Information & service agreements

Confirm where connected services process data, what they may use it for, how long they keep it and which agreements apply.

Staff operations

Assign staff to review exceptions, investigate uncertain results and respond to privacy or security requests. A request in the queue still needs someone to accept and handle it.

Before using patient data

Check what your facility
requires before rollout.

Korenact does not claim HIPAA, SOC 2 or HITRUST certification. Single sign-on, multi-factor authentication, automated deletion across all records and a published service-level agreement are not included in this release.

Before handling regulated or confidential information, review security, privacy and contractual requirements. Confirm that the required agreements and controls are in place.

Questions for your facility’s review

  • Who needs access, and to which information?
  • Which actions need staff approval?
  • Where are data and backups stored?
  • What retention and recovery process is required?
  • Which service agreements must be in place?
Discuss your security requirements

To report a security concern, request a private follow-up. Share a brief description first; do not include passwords, credentials or another person’s private information.

Discuss a pilot

Discuss your facility’s requirements.

Bring your questions about user access, patient information, hosting and staff responsibilities.

Plan a healthcare pilot