Security & Data Handling
Last updated September 3, 2026
Our approach
More Business operates customer lead workflows that may include contact details, communications, qualification information, call recordings, and appointment data. We use administrative and technical safeguards designed to limit access, preserve accountability, and support the requirements of each engagement.
Access and accountability
Access is assigned according to role and operational need. Supported workflows use role-based permissions and user activity logs. Team members receive access only to the systems and customer information required for their work, and access can be changed or removed as responsibilities change.
Data protection
Our core communications infrastructure supports encryption of stored data using AES-256, regular encryption-key rotation, encrypted transmission, and controlled user access. We configure customer workflows to minimize unnecessary data collection and use established systems rather than duplicating customer records without an operating need.
Communications and recordings
Lead and patient communications may occur by phone, SMS, and email according to the approved workflow. Calls may be recorded for quality assurance, coaching, documentation, and dispute resolution, subject to applicable law and customer instructions. Customers are responsible for required notices and approvals specific to their business and jurisdiction.
More Medical and HIPAA
More Medical uses HIPAA-enabled infrastructure for patient lead-management workflows involving protected health information. The enabled environment includes technical and administrative safeguards designed to support HIPAA-compliant use, including encryption, role-based access controls, and activity logging.
A Business Associate Agreement is available when required for the services and workflow in scope. HIPAA compliance is a shared operational responsibility: More Business configures and operates the agreed lead workflow, while each covered entity remains responsible for its own policies, workforce, authorizations, clinical systems, minimum-necessary determinations, and lawful use of patient information.
Customer systems and integrations
More Business is designed to work with a customer’s existing lead sources, calendar, and operating tools. Any integration is scoped during implementation. A connected third-party system remains subject to that provider’s security, availability, and contractual terms.
Incident response
Suspected unauthorized access, disclosure, loss, or misuse should be reported promptly to [email protected]. We investigate reported events, take reasonable containment and remediation steps, and provide notices required by applicable agreements or law.
Questions and diligence
Security, compliance, and BAA questions can be sent to [email protected]. Additional workflow-specific information can be addressed during contracting and implementation.