Compliance | Atel Q | Data Protection & Healthcare Compliance
Compliance

Data Protection & Healthcare Compliance

The compliance framework applied to Atel Q Voice AI deployments in the United Kingdom and to qualifying healthcare deployments in the United States.

United Kingdom

UK deployments are operated under Atel Q's data-protection framework, designed to support compliance with UK GDPR and the Data Protection Act 2018, as amended.

United States healthcare

HIPAA-enabled deployment is available where a qualifying US healthcare organisation requires Atel Q to process Protected Health Information.

Compliance controls are applied according to jurisdiction, the type of information being processed and the role Atel Q performs within the deployment. Enhanced healthcare controls are enabled before regulated patient information is introduced where required.

Regulatory framework

How the framework is applied

United Kingdom

UK GDPR

Where Atel Q processes personal information on a client's instructions, the client will normally act as Data Controller and Atel Q as Data Processor, subject to the actual processing arrangement.

Health information is treated as special category personal data and is handled with the additional safeguards appropriate to that data.

United States healthcare

HIPAA-enabled deployment

For qualifying US healthcare organisations, Atel Q can activate a separate HIPAA-enabled deployment before the service begins creating, receiving, maintaining or transmitting PHI.

Required Business Associate arrangements, security controls and deployment checks are completed before production PHI is introduced.

Operational safeguards

Core controls

These controls form the baseline for Atel Q deployments and are strengthened where regulated healthcare information is involved.

01

Data minimisation

Voice AI workflows are configured to collect only information needed for the relevant interaction, workflow or authorised business purpose.

02

Purpose limitation

Client data is processed for agreed services and authorised workflows and is not intentionally repurposed for unrelated activities.

03

Access control

Access to client environments and sensitive information is restricted according to operational need and authorised user responsibilities.

04

Account security

Administrative access is protected by appropriate authentication and account-security controls, with enhanced requirements for regulated deployments.

05

Auditability

Where required, activity can be evidenced through interaction records, workflow history, system logs and authorised-user activity.

06

Retention & incident response

Retention is configured according to purpose, contractual and legal requirements. Security incidents are assessed and escalated under the applicable response process.

Healthcare information

Handling patient-related information

Patient identity and contact information
Appointment and scheduling information
Call recordings, transcripts and summaries
Treatment-related enquiries and patient requests
Referral, complaint and administrative information

Minimum necessary information

Healthcare workflows are configured to avoid unnecessary collection of clinical detail. The client's clinical or practice-management system remains the authoritative clinical record unless a different arrangement is expressly agreed.

HIPAA deployment

When HIPAA is switched on

HIPAA controls are not activated simply because a service is being discussed, demonstrated or tested. They are enabled before a qualifying US healthcare deployment begins processing production PHI.

ScenarioHIPAA status
UK healthcare deployment operating under UK data-protection requirementsUK framework applies
Sales discussion, demonstration or testing using synthetic or non-patient dataNo HIPAA activation required
US dental or healthcare practice assessing the service before production useHIPAA-ready deployment demonstrated
Qualifying US healthcare practice will process real patient PHI through Atel QHIPAA activation required before go-live
An existing deployment is changed so that it will begin processing production PHIHIPAA activation required before the change goes live
Activation process

HIPAA-enabled deployment sequence

01

Confirm applicability

Confirm the client's HIPAA status, intended use and whether PHI will be processed.

02

Complete agreements

Put the required Business Associate and contractual arrangements in place through the delivery chain.

03

Enable HIPAA controls

Activate Atel Q's HIPAA-enabled healthcare environment for the relevant deployment instance.

04

Review access

Confirm authorised users, permissions, administrative access and operational responsibilities.

05

Validate workflows

Review Voice AI, data capture, communications, escalation and handling rules against the approved healthcare configuration.

06

Test & go live

Complete pre-live testing without production PHI. Live patient information is introduced only after the environment is approved for use.

Commercial terms

HIPAA-enabled deployment fee

Additional recurring charge

HIPAA-enabled operation carries an additional monthly fee.

The fee reflects the additional regulated infrastructure, contractual arrangements, security controls and ongoing compliance management required for a HIPAA-enabled deployment.

The recurring fee applies per deployment instance and begins when HIPAA controls are activated for that instance. It is additional to the standard Voice AI service charge.

Deployment instance: a separately configured Atel Q Voice AI environment associated with a particular practice, brand, website, location or separately configured service. A single organisation may therefore operate more than one deployment instance.

No HIPAA-enabled deployment fee applies solely for proposals, demonstrations or pre-production testing that does not use production PHI. The applicable monthly fee is confirmed before activation.

Roles & responsibilities

Compliance is shared across the deployment

Atel Q's controls operate alongside the responsibilities of the organisation using the service.

Atel Q

  • Configures the service according to agreed data-handling requirements.
  • Applies appropriate access, workflow and security controls within the Atel Q environment.
  • Processes client-controlled information in accordance with the agreed service and contractual arrangements.
  • Supports applicable incident, deletion and data-handling obligations within Atel Q's scope.

Client organisation

  • Determines the lawful basis and permitted purposes for its processing.
  • Maintains required privacy notices, patient policies and clinical governance.
  • Controls access provided to its personnel and identifies its retention requirements.
  • Provides accurate processing instructions and confirms jurisdiction-specific obligations.
Regulatory basis

Official guidance

Atel Q's compliance framework is informed by guidance issued by the UK Information Commissioner's Office and the U.S. Department of Health & Human Services.

This page describes Atel Q's standard data-protection and healthcare compliance framework. Specific deployments may require additional contractual, technical or organisational measures depending on jurisdiction, data type, processing role and client requirements. Use of Atel Q does not remove or replace a client's own regulatory obligations.

Last updated: September 2026