Skip to content

Healthcare AI requires healthcare-grade thinking.

Patient information is not the same as restaurant bookings or e-commerce orders. We design around that from the start, whether your clinic is in Houston, São Paulo, Toronto or Dubai.

Your clinic’s system runs in your clinic’s accounts.

There is no shared platform behind this and no central database holding one clinic’s patients next to another’s.

  • Their own workspace

    A separate automation workspace with its own workflows. Nothing is shared with another clinic.

  • Their own credentials

    The AI provider key, the WhatsApp Business account and booking-system access all sit under the clinic's own billing.

  • Their own staff channel

    A private channel where the team watches conversations and takes over. No other clinic can see it.

  • Their own configuration

    Services, prices, staff routing, opening hours and escalation rules, set for that clinic and nobody else.

And if we stop working together

You keep a working system. We hold an administrator role on your accounts, not your patient data, and that role is removed on request. Nothing has to be migrated off our platform, because it was never on our platform.

Worth asking any vendor: where do patient conversations actually live, and what are you left holding if you leave?

Healthcare data stays in your accounts, under your country’s rules.

Compliance belongs to a specific deployment: its vendors, contracts, data flows and your policies. Here is what we design around in each market. We confirm the rest with you during implementation.

Regulatory frameworks by market
North America
  • HIPAA (United States)
  • PIPEDA (Canada)
Systems handling protected health information are designed around HIPAA privacy and security requirements, with Business Associate Agreements in place with vendors where required.
South America
  • LGPD (Brazil)
  • Local data-protection laws
Lawful basis, consent and data-subject rights are designed around the law that applies in each country, confirmed with you during implementation.
UAE and GCC
  • Federal Decree-Law No. 45 of 2021 (PDPL)
  • DHA, DoH and MOHAP requirements
  • Federal Law No. 2 of 2019, ICT in health fields
Deployments follow UAE health-data requirements, including where patient information is stored and processed. Residency is set per client.
Europe
  • GDPR
Lawful basis agreed with the clinic, a data-processing agreement, documented subprocessors, retention limits and support for erasure requests.
Read how we protect patient data

Six things we decide before we build.

  1. 1

    Privacy by design

    Where patient information goes is settled before anything is built. That decides the architecture, and it is why each clinic gets its own deployment.

  2. 2

    Data minimization

    Analytics record that a conversation happened, in what language, about which service and with what outcome. Not who it was or what was said.

  3. 3

    Access control

    Named clinic staff and an MHub administrator role. No standing access for anyone who doesn't need it, removed at the end of an engagement without being asked.

  4. 4

    Secure integrations

    Every connection runs on the clinic's own credentials over the vendor's official API. No scraping, no shared keys, no back doors.

  5. 5

    Healthcare-specific architecture

    Escalation rules, disclosure limits and human oversight are structural here, not settings.

  6. 6

    Human oversight

    A person can always see what is being said and step in. Complaints and medication questions reach a human without the patient having to ask.

The questions a practice manager asks.

Where is our patient data stored?

In your own accounts. Conversations sit in your messaging account, appointments in your booking system and analytics in a workspace you own. MHub does not hold patient data in a central system.

Is this HIPAA compliant?

For US deployments we design around HIPAA privacy and security requirements: isolated infrastructure under your control, minimal data collection, access limited to named staff, and Business Associate Agreements with vendors where required. Whether a specific deployment meets HIPAA depends on its final configuration, vendors and your own policies, so we confirm it during implementation rather than claim it in advance.

Can it give medical advice?

No, and it is prevented from trying. Diagnosis requests, medication questions, complaints and insurance queries are routed to your staff automatically.

Find out where your enquiries slip away.

A free automation audit of your enquiry and booking process, with practical next steps whether you work with us or not.

The MHub team

Share business information only. We never need patient records for an audit.

Prefer email? team@mhubsolutions.tech