ContactBook free analysis
Secure AI for medical & dental practices

HIPAA-compliant, on-premise AI for medical & dental practices.

You run a practice that holds PHI. Your staff can use AI on it without a BAA gap or a third-party disclosure.

On-premiseYou own it14-day money-back guarantee
The problem

Your front desk is using a chatbot with no BAA behind it.

Consumer ChatGPT, Gemini and Claude are not BAA-eligible, so entering PHI is an impermissible disclosure — not a policy question. OCR's 2025 enforcement wave issued penalties from $25K to $3M, much of it for risk-analysis failures rather than breaches. And the exposure is created quietly: one staff member pasting a chart note into a browser tab, with nothing in your audit log to show it happened.

Primary sources
The solution

You get a private AI over your own records, in a chat window your staff already understand.

Private chart & records Q&A

Ask across charts, referral letters and scanned records held in your systems. PHI is read on your hardware and never transmitted.

Dictated notes → drafted documents

Dictation becomes a drafted note, referral letter or patient instruction in your template, ready for the clinician to sign.

Intake & prior-auth summarization

Intake packets and payer requirements summarized into the exact fields your prior-auth submission asks for.

Dental: back office and records, not clinical imaging

Overjet and Pearl read radiographs. This is the other half of the practice: records Q&A, treatment-plan letters, insurance narratives and recall lists — across a four-location group, on one appliance.

How it works

From analysis to a running system in your office.

01

You tell us where the hours go

A free 30-minute analysis. We say where a private AI pays for itself in your firm — and say so if it doesn’t yet.

02

You approve the build

You see the whole number before anything is ordered. The system is engineered to your workflows, not a template.

03

You get it installed

In your building. Encryption, SSO + MFA and audit logging, documented for your compliance file.

04

You stop thinking about it

24/7 monitoring, model updates and document-pipeline upkeep on one flat monthly plan.

What a build includes

Charts, referral letters and scanned records, readable on hardware you own.

Indexed from the systems you already run, behind SSO and MFA, with every prompt and document read written to your audit log. The control narrative and network diagram are documented for your risk analysis.

See the healthcare workload →
needed — there is no third party
No BAA
PHI leaving your network
0
to change your mind, hardware included
14 days
Own it

One price to own it. 14 days to be sure.

One room
$12,000 – $24,000
+ $1,000–$2,500/mo
Whole floor
$32,000 – $56,000
+ $2,500–$5,000/mo
Every floor
Custom
monthly quoted with the build
14
days, money back
Every dollar — hardware included. Signed into the build agreement, not a footnote.
Compliance controls

Documented for your compliance file.

Encryption at rest
Full-disk encryption on every drive in the appliance. Keys held by you.
TLS in transit
TLS 1.3 between the chat client and the appliance. Nothing crosses your perimeter.
SSO + MFA
Binds to the identity provider you already run — Entra, Okta or Google Workspace.
Audit logging
Every prompt, document read and answer written to your log store. Retention is your policy.
Data never leaves
No outbound inference calls. Prompts, files, embeddings and outputs stay on the box you own.
Documented for your file
Control narrative, network diagram and configuration handed over as a PDF for your compliance binder.
On-premise is not, by itself, a compliance programKeeping inference in the building removes third-party-disclosure risk — the largest single item. You still need written policy, staff training and a current risk assessment. We hand over the technical control documentation; your counsel or compliance officer owns the program.
FAQ

Healthcare — the questions we get asked.

Is using ChatGPT a violation of HIPAA?
Entering PHI into consumer ChatGPT is a disclosure to a party with no BAA, which HIPAA does not permit. De-identified data is a different matter, but de-identification is harder than it looks — dates, rare diagnoses and free-text notes re-identify easily. On-premise inference avoids the question: there is no third party to disclose to.
Are doctors allowed to use ChatGPT?
For non-PHI work — literature summaries, drafting policy, learning — yes. For anything patient-identifying, you need either a BAA-eligible enterprise service or a system inside your own network. The rule follows the data, not the job title.
Is there an AI that is HIPAA compliant?
No model is “HIPAA compliant” by itself; the deployment is what complies. A private model on hardware you own, with encryption, access control and audit logging, satisfies the Security Rule's technical safeguards and removes the disclosure question the Privacy Rule asks.
What is the best AI for a medical practice?
The best one is the one your staff will actually use that doesn't create a disclosure. In practice that means an open-weight model on-site, indexed over your own records, in a chat window that behaves like the tools they already know.
How can I use AI in my medical practice?
Start where the documentation burden is heaviest: notes, referral letters, prior authorization, records lookup. Those are back-office wins with no clinical-decision risk, and they are the fastest to pay for the system.

Thirty minutes, and you’ll know whether this is worth doing.

Sarasota · Bradenton · Lakewood Ranch · Venice · the Suncoast