I spend my days as an Information System Security Manager for a DoD contractor. My job is protecting classified information. So when I tell you that your customer data is safe with AI automation - I’m not making a marketing claim. I’m making a professional assessment.
I hold a CISSP and a CISM. These are the same certifications required to manage security for classified military systems. I’ve spent years ensuring that the information entrusted to government systems stays protected against nation-state threats.
I’m telling you this not to name-drop acronyms but to establish something important: I take data security seriously as a career, not just as a talking point. And I built Solas AI with that same standard in mind.
So let’s address your concerns directly.
”Where Does My Customer Data Go?”
This is the most common question I hear, and it’s the right one to ask.
Here’s the straightforward answer: your data stays in your systems. When we set up automation for your business, your customer records live in your database - typically Supabase or your existing CRM. That data belongs to you. It sits on infrastructure you control.
When AI processes a task - sending a reminder, answering a phone call, generating a follow-up message - it accesses only the specific data points it needs for that task. A reminder system needs the patient’s first name, phone number, and appointment time. It doesn’t need their medical history, social security number, or payment information.
The AI processes the information, completes the task, and moves on. It doesn’t build a shadow copy of your customer database. It doesn’t train itself on your data. It doesn’t share your information with other businesses.
Your data goes exactly where you’d expect it to go: nowhere it shouldn’t.
”Can AI Leak Patient Records?”
This is really a question about access control, and it’s a question I deal with professionally every single day.
Properly configured AI automation follows the principle of least privilege - the same principle that governs classified systems. Every component gets access to the minimum data required to do its job. Nothing more.
Your appointment reminder system can see appointment times and contact information. It cannot see clinical notes. Your review request system can see that a service was completed. It cannot see what procedures were performed.
These aren’t honor-system restrictions. They’re architectural ones. The systems are built so that unauthorized data access isn’t just discouraged - it’s not possible within the design.
API calls between systems are encrypted in transit using TLS. Data at rest is encrypted in your database. These are the same encryption standards used by banks, hospitals, and yes, military systems.
Could a poorly built system leak data? Absolutely. That’s true of any software, AI or otherwise. Which is why who builds your system matters as much as what they build.
”What About HIPAA?”
If you’re a dental practice, medical office, or any business handling protected health information, HIPAA compliance isn’t optional. You already know this.
Here’s what HIPAA actually requires for AI automation: a Business Associate Agreement (BAA) with any service that touches PHI. Encrypted data transmission. Access controls. Audit logs. Breach notification procedures.
All of these are standard in a properly architected system. BAAs are available from the major AI and cloud providers. Encryption is a configuration choice, not a technical limitation. Audit logs are built into modern databases by default.
The real HIPAA risk in most small practices isn’t their software. It’s their daily habits. But I’ll get to that in a moment.
The Irony Nobody Talks About
Here’s what I find genuinely concerning as a security professional. Most service businesses worried about AI security are currently running operations that would fail a basic security audit.
Let me ask you a few questions:
- Do you or your staff ever email patient information using standard, unencrypted email?
- Does more than one person share a login to your practice management software?
- Do you have paper records with patient information sitting in unlocked filing cabinets?
- Has every staff member with system access completed security awareness training in the past twelve months?
- Do you have a documented process for revoking access when an employee leaves?
If you answered “yes” to the first three or “no” to the last two, your current manual processes present a bigger data risk than any AI system would.
Unencrypted email is the single most common HIPAA violation in small healthcare practices. Not AI. Not automation. Email.
Shared passwords mean you can’t track who accessed what information and when. If a breach occurs, you can’t identify the source. That’s a compliance nightmare.
Paper records in unlocked cabinets are accessible to every person who walks into your office - cleaning crew, delivery drivers, anyone.
I’m not saying this to make you feel bad. I’m pointing out that the security bar for AI automation is often higher than the security bar for the manual processes it replaces.
What Proper Security Actually Looks Like
When I architect a system for a Solas AI client, here’s what’s in place from day one:
Encryption everywhere. Data encrypted in transit between every system. Data encrypted at rest in your database. No exceptions.
Role-based access control. Every automation has a defined scope. The reminder system accesses contact info and appointments. The review system accesses service completion records. Nothing crosses boundaries.
Audit logging. Every data access is logged. If you ever need to demonstrate compliance - to a HIPAA auditor, to an insurance provider, to yourself - the records are there.
Your data, your infrastructure. Customer records don’t live on our servers. They live on yours. You maintain ownership and control at every point.
No training on your data. AI models don’t learn from your customer information. Your patient records don’t improve someone else’s product.
The Real Question
The question isn’t whether AI is safe. The question is whether your current manual processes are safe.
A properly built automation system with encryption, access controls, and audit logging is measurably more secure than spreadsheets emailed between staff members, paper files in open cabinets, and shared passwords on sticky notes.
I don’t ask you to trust AI because it’s trendy. I ask you to evaluate it against the alternative - and make a decision based on the actual risk profile of each option.
That’s what a security professional does. And that’s the standard I hold every system we build to.
Want to know more about how I approach security? Learn about my background and credentials on our About page.
Have specific security questions about your industry? Book a 15-minute call and I’ll walk through exactly how your data stays protected. No sales pitch - just a security briefing from someone who does this for a living. solasai.net/book