What Fini provides
Request a BAA
1
Tell your Fini contact you need a BAA
Ask your Fini account team, or email legal@usefini.com, and say which workspace and agents will handle PHI.
2
Review and sign
Review the BAA alongside the Data Processing Addendum with your privacy or compliance team.
3
Configure before go-live
Apply the recommendations below in a test workspace or with test data, run the Test Suite, and only then connect channels that carry real patient conversations.
What you are responsible for
The BAA covers Fini’s obligations. These recommendations cover yours. None of them is legal advice; your compliance team decides what your use of Fini requires.Send only the data the agent needs
The agent sees whatever your knowledge sources, User Attributes and connected channels give it. Apply minimum necessary at the source:- User Attributes. Expose only the fields a workflow actually uses (plan, appointment status, device sync state). Don’t return diagnosis codes, clinical notes or full medical history from your attributes endpoint because they might be useful someday. See Attributes.
- Knowledge sources. Train the agent on policies, help articles and procedures, not on documents that contain patient records. Review what you sync from Google Drive, Notion or file uploads. See Knowledge sources.
- Actions. Scope each Action to one job, and keep destructive Actions behind confirmation steps in the Rulebook. See Actions.
Keep PHI values out of replies
Add a Confidential attributes guardrail and select the attribute keys whose values must never appear in a reply, such as date of birth, member ID or medical record number. The check matches the actual values for that customer; it is not blanket detection of all personal data, so pair it with a Custom rule describing what the agent must never disclose. See Guardrails.Route clinical questions to people
Fini is a support agent, not a clinical tool. Layer these controls so medical questions go to your team instead of getting an AI answer:- Add clinical advice, symptoms and medication questions to the Escalation Topics subsection of the Planning Prompt’s Knowledge Search – Decision Logic section. Medical emergencies and self-harm are already in Fini’s default triggers. See Prompts.
- Add a Custom rule guardrail that fails any reply giving diagnosis, dosage or treatment guidance.
- Use a Reply Rule on the Internal Comment card for clinical tag values, so even a misrouted conversation produces a note for your team rather than a customer-facing reply. See Reply Rules.
Control who can see conversations
- Turn on Okta SSO and assign only the staff who need dashboard access. Removing someone from the SAML app removes their access.
- Use one API key per integration, with
readonly where possible, and revoke keys when an integration or teammate leaves. - Inbox mirrors conversations from your connected helpdesk, including human-agent replies and internal notes. Anyone with dashboard access can see them, so treat dashboard access like helpdesk access.
Handle deletion and access requests
When a patient asks for their data to be deleted, delete the matching conversations with the Delete conversation or Bulk delete conversations endpoints, and delete the source record in your helpdesk too. See Data handling for retention defaults.Test before you ship
Build a test set with the Safety & boundaries and Escalation behavior judges and seed it with clinical and PHI-sharing scenarios. Run it after every prompt, knowledge or rule change. See Test Suite.Cover the rest of your stack
Fini connects to your helpdesk, telephony and messaging tools. Your BAAs with those vendors, and your own HIPAA program, are outside Fini’s BAA.Related
Healthcare setup
Recommended agent configuration for health and health-tech support teams.
Data handling
Residency, encryption, retention, deletion and DPA terms.
Guardrails
Confidential attributes, banned terms and custom rules.
Security overview
Fini’s full security posture and how to request reports.

