Security & HIPAA

Built for dental PHI.
Not retrofitted from a generic file tool.

Intake.Dental Send was designed by a practicing dentist around the way real offices share patient records — and around the parts of HIPAA that actually matter for that workflow.

  • HIPAA-compliantBAA included
  • AES-256 encryptedIn transit & at rest
  • Auto-expires7 days, then deleted
  • Free for dentalBuilt by a dentist

End-to-end encryption — on by default

New transfers are encrypted in your browser with AES-256-GCM before a single byte is uploaded — our servers only ever store ciphertext. The decryption key stays between you and your recipient: it rides the share link's URL fragment (which browsers never send to any server), or is unlocked by the PIN you share out-of-band. Decryption happens on the recipient's device, including the built-in X-ray viewer.

Encryption — in transit and at rest

Every upload runs over TLS 1.3 to a US-region server. Files are written to encrypted object storage with AES-256. Database fields containing identifiers are field-level encrypted with rotating keys. There is no point in the lifecycle where your patient files sit in plaintext on a disk we can read.

Two-factor by design — link + PIN

The download link goes to the recipient's email. The 4-digit PIN is communicated out-of-band — you text or call it. An attacker who compromises the recipient's inbox alone cannot open the package. This is HIPAA's "access control" rule, applied to a workflow your staff actually uses.

Auto-expiry and deletion

Every transfer expires 7 days after sending. Expired files are removed from object storage and rendered unrecoverable. We never indefinitely retain your patient files. If you need a permanent record, that should live in your PMS — not a transfer service.

No PHI in subject lines or messages

Subject lines you set are visible only to you, the sender. Recipients see a generic email — "A secure file is waiting for you" — until they enter the PIN. Patient names and details never leak into mail headers, server logs, or push notifications.

BAA included, automatically

Every account accepts our Business Associate Agreement on first sign-in. There is no separate procurement process, no PDF to print and fax. Your BAA is on file, dated, and downloadable from your dashboard at any time.

Audit trail

Every transfer keeps an audit log: who sent it, who opened it, when, and from what IP. If you ever need to demonstrate to a covered entity or auditor that a specific file went to a specific recipient, the record exists.

Need our BAA before you start?

You can read the full Business Associate Agreement at intake.dental/baa. You'll be asked to accept it electronically when you verify your email — no paperwork required.

Send a file with confidence

Free for dental practices. BAA in place automatically.

Get started