Security

Clinic trust has to be built into the product.

Caira Health is designed around clinic isolation, secure payments, auditability, practical privacy operations, and human-reviewed AI.

Clinic-scoped access

Every staff-facing action resolves the active clinic and scopes records by clinic ID.

Payment safety

Card-on-file uses Stripe. Raw card numbers never belong in the application database.

Operational auditability

Patient records, billing actions, and sensitive changes are designed to be reviewable.

Human-reviewed AI

AI drafts and receptionist handoffs do not replace clinical judgment or staff approval.

Where is patient data stored?

Caira Health is built for Canadian data residency. The app also keeps staff access clinic-scoped so one clinic cannot access another clinic's data.

How does Caira Health handle security and PHI?

Access is role-aware, clinic-scoped, and designed around auditability. Payment details are handled by Stripe, and Caira Health does not store raw card numbers.

Can we switch from spreadsheets or another system?

Yes. CSV import tooling is planned for patients and appointments, and our team helps clinics bring across larger imports before going live.

How safe are the AI features?

AI drafts notes, summaries, and call handoffs. Staff review before anything is signed, sent, or used with a patient.

Does SMS work for reminders?

Email reminders are included on every plan. SMS reminders are available on the Practice plan and up, and start sending once the clinic's messaging setup is complete.

Is there a trial or contract?

Every plan starts with a 14-day free trial and no long-term contract. Billing is monthly by default and you can cancel anytime; annual billing is available at a discount if you prefer.