Fini (usefini.com) is HIPAA-compliant, with a Business Associate Agreement (BAA) available to healthcare customers. Sign the BAA before any protected health information (PHI) reaches Fini, then use the configuration on this page so your agent handles PHI only where it needs to and routes clinical questions to people. HIPAA compliance is shared. Fini is responsible for how its platform stores, protects and processes data as your business associate. You are responsible for what you send to Fini, which conversations the agent answers, and how your workspace is configured. This page covers both halves.

What Fini provides

To confirm (internal, remove before publish): Which subprocessors that may receive PHI (for example OpenAI, Anthropic, Google Cloud, Supabase) are covered by downstream BAAs, and can we say so on this page? Healthcare reviewers will ask for the BAA chain.

Request a BAA

1

Tell your Fini contact you need a BAA

Ask your Fini account team, or email legal@usefini.com, and say which workspace and agents will handle PHI.
2

Review and sign

Review the BAA alongside the Data Processing Addendum with your privacy or compliance team.
3

Configure before go-live

Apply the recommendations below in a test workspace or with test data, run the Test Suite, and only then connect channels that carry real patient conversations.
To confirm (internal, remove before publish): What is the exact BAA process? (1) Who to contact: account team, legal@usefini.com, or a Trust Center request. (2) Is it Fini’s standard BAA template, or do we accept customer paper? (3) Typical turnaround. (4) Is the BAA available on every contract, or only on certain deployment or contract types? (5) Must it be signed before PHI is sent, and does Fini enforce that on the workspace?

What you are responsible for

The BAA covers Fini’s obligations. These recommendations cover yours. None of them is legal advice; your compliance team decides what your use of Fini requires.

Send only the data the agent needs

The agent sees whatever your knowledge sources, User Attributes and connected channels give it. Apply minimum necessary at the source:
  • User Attributes. Expose only the fields a workflow actually uses (plan, appointment status, device sync state). Don’t return diagnosis codes, clinical notes or full medical history from your attributes endpoint because they might be useful someday. See Attributes.
  • Knowledge sources. Train the agent on policies, help articles and procedures, not on documents that contain patient records. Review what you sync from Google Drive, Notion or file uploads. See Knowledge sources.
  • Actions. Scope each Action to one job, and keep destructive Actions behind confirmation steps in the Rulebook. See Actions.

Keep PHI values out of replies

Add a Confidential attributes guardrail and select the attribute keys whose values must never appear in a reply, such as date of birth, member ID or medical record number. The check matches the actual values for that customer; it is not blanket detection of all personal data, so pair it with a Custom rule describing what the agent must never disclose. See Guardrails.

Route clinical questions to people

Fini is a support agent, not a clinical tool. Layer these controls so medical questions go to your team instead of getting an AI answer:
  • Add clinical advice, symptoms and medication questions to the Escalation Topics subsection of the Planning Prompt’s Knowledge Search – Decision Logic section. Medical emergencies and self-harm are already in Fini’s default triggers. See Prompts.
  • Add a Custom rule guardrail that fails any reply giving diagnosis, dosage or treatment guidance.
  • Use a Reply Rule on the Internal Comment card for clinical tag values, so even a misrouted conversation produces a note for your team rather than a customer-facing reply. See Reply Rules.

Control who can see conversations

  • Turn on Okta SSO and assign only the staff who need dashboard access. Removing someone from the SAML app removes their access.
  • Use one API key per integration, with read only where possible, and revoke keys when an integration or teammate leaves.
  • Inbox mirrors conversations from your connected helpdesk, including human-agent replies and internal notes. Anyone with dashboard access can see them, so treat dashboard access like helpdesk access.

Handle deletion and access requests

When a patient asks for their data to be deleted, delete the matching conversations with the Delete conversation or Bulk delete conversations endpoints, and delete the source record in your helpdesk too. See Data handling for retention defaults.

Test before you ship

Build a test set with the Safety & boundaries and Escalation behavior judges and seed it with clinical and PHI-sharing scenarios. Run it after every prompt, knowledge or rule change. See Test Suite.

Cover the rest of your stack

Fini connects to your helpdesk, telephony and messaging tools. Your BAAs with those vendors, and your own HIPAA program, are outside Fini’s BAA.

Healthcare setup

Recommended agent configuration for health and health-tech support teams.

Data handling

Residency, encryption, retention, deletion and DPA terms.

Guardrails

Confidential attributes, banned terms and custom rules.

Security overview

Fini’s full security posture and how to request reports.