Security & Transparency

Built with security in mind. Transparent about where we are with HIPAA.

Mia is not currently offered or represented as a HIPAA-compliant service. Dos Tiris has implemented technical safeguards designed to protect information, but security safeguards alone do not establish HIPAA compliance.

Our current HIPAA status

Dos Tiris does not currently claim that Mia is HIPAA compliant. Until Dos Tiris confirms a compliant service configuration and any required agreements are in place, practices should not use Mia for workflows that require HIPAA-compliant handling of protected health information.

AWS-hosted production infrastructure

Mia's production application and database run in Amazon Web Services. Production application resources are separated from the public marketing website and protected by controlled network and application boundaries.

Encryption

Mia uses encrypted HTTPS connections for production web traffic, and its production database is configured with encryption at rest.

Access controls

Owner and office-portal functionality requires authenticated access. Backend permissions are limited according to the operations each application component needs to perform.

Practice separation

Mia is designed around separate dental-practice tenant contexts. Tenant boundaries and authorization behavior are tested as part of the application's quality and release process.

PHI minimization

Mia is designed to minimize unnecessary patient information sent to AI model services. Identity, appointment, calendar, and operational information is kept in the application and database layer whenever possible.

Controlled AI architecture

Mia uses Amazon Bedrock as its primary production AI service. The application controls what information is provided to the model instead of exposing the complete application database or patient record.

Security and HIPAA compliance are not the same thing

Security safeguards are an important part of protecting information. HIPAA compliance can also involve contractual, administrative, operational, and legal requirements. Using AWS or other security-focused technology does not, by itself, make a service HIPAA compliant.

We prefer to state Mia's current status clearly instead of using its security architecture to imply a compliance status that has not yet been established.

Questions about Mia's security?

Dental practices evaluating Mia can contact Dos Tiris for information about the current architecture, safeguards, and service requirements.

Contact Dos Tiris

Last updated: September 2026.