Built for HIPAA from the ground up. Not bolted on after.
Mandi was designed in partnership with dentists, by the son of one, a cybersecurity expert with enterprise defense-industry experience. Your patient data is treated the same way aerospace systems treat classified access: by construction, not by policy.
What's built in, not bolted on.
Tenant isolation by construction
Cross-tenant reads are structurally impossible by construction: every query is tenant-scoped through a tenant-bound data adapter. Each practice's data is strictly isolated.
Human-in-the-loop writes
AI proposes; staff confirms; nothing executes automatically. No rogue scripts modifying your schedule.
AI sandbox boundaries
The AI never touches the database directly. It only calls a whitelisted, tightly constrained set of validated tools.
Minimum-necessary to AI
Patient names are masked as "First L." Phone numbers, emails, and DOBs never reach the language model at all.
PHI-scrubbed logs
Aggressive filtering ensures patient data cannot accidentally land in application or server logs.
Tamper-evident audit trail
Every action and every read is logged, tenant-scoped, and securely retained for compliance auditing.
Encrypted end to end
Every connection is TLS-encrypted and all data is encrypted at rest with customer-managed keys (CMEK). Nothing sits in plaintext.
Enterprise authentication
Single sign-on and multi-factor auth, role-based access control, and automatic session expiry. No shared logins, no standing access.
Signed provider agreements
A signed Business Associate Agreement with Google Cloud, the sole infrastructure provider that processes patient data. Our identity provider never receives patient data and is governed by a data-processing agreement.
We sign a BAA before anything else.
Before any real patient data flows through Mandi, we execute a fully signed Business Associate Agreement with your practice. Building for HIPAA isn't a feature; it's the foundation. We won't cut corners on this, and we won't ask you to either.
On our security roadmap
The safeguards above are built and running today, backed by a documented risk analysis, written security policies, and a designated Security Officer. Here's what's next as we scale beyond our initial pilot practice.
- SOC 2. Controls are mapped across all five trust-services criteria. A Type II audit is not required for our Dentrix integration; we may pursue one as we move upmarket.
- Independent assessment. An independent third-party HIPAA assessment as we scale beyond our initial pilot practice.
Talk to our security team
Have specific compliance requirements or technical questions? We're happy to discuss our architecture in detail.
Email security@heymandi.ai