Skip to main content
Fini (usefini.com) is HIPAA-compliant and BAA-eligible for enterprise customers, and setting it up for healthcare means configuring the agent so it sees and repeats as little protected health information (PHI) as each workflow needs: identify patients through a signed widget token, expose only the attributes a rule uses, never ask for health details a workflow doesn’t need, keep PHI-bearing values out of replies with the Confidential attributes guardrail, and route clinical questions and PHI-sensitive requests to your team. Fini then resolves the administrative volume, such as scheduling, portal access, billing questions, and office information, while Reply Rules, Escalation Topics, and Guardrails keep clinical judgment with people. This page is the configuration playbook. The recommendations below are configuration choices you make in your workspace, not a description of HIPAA obligations; have your privacy officer review them against your own policies. For what Fini does for healthcare as a product, see usefini.com/industries/healthcare.

Compliance pointers

Request the BAA through your Fini account team; typical turnaround is about one week, and Fini’s template or your own both work. Put it in place before any PHI reaches the agent, including during pilots and Test Suite runs on real transcripts. Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. Don’t ask patients for health details the workflow doesn’t need. The Guardrails in step 6 are an extra layer on what the agent says.

1. Expose the minimum necessary attributes

User Attributes are the main way patient data enters the agent’s context. For each collected field, choose the switches deliberately:
  • Use in Rulebooks only for fields a Check or Tool input needs, such as patient_id or has_upcoming_appointment.
  • Visible to AI only for fields the agent must mention in a reply, such as the date and location of the next appointment. Leave it off for identifiers, diagnoses, medications, and insurance member numbers.
  • Don’t collect what no rule uses. Fields that never appear in a rule or reply don’t belong in the Save From Response mapping.
See the switch-by-switch pattern in End-to-end: cancellation flow, where the internal customer_id is used in rules but kept out of the model’s view.

2. Scope knowledge

  • Separate agents for separate audiences. A patient agent and a provider or partner agent should retrieve from different folders. See Knowledge → Agent-specific scoping.
  • Attribute Filters for location- or plan-specific content, for example state = California or plan = Medicare Advantage. See Articles → Attribute filters.
  • No PHI in articles. Articles are shared across every conversation the agent handles. Write them as general policy and procedure, never with patient examples.

3. Tag clinical and PHI-sensitive intents

Create a custom group with Tag Group available in Rulebooks on and Tag Selection set to “Multiple tags can be selected”: Add QA groups that follow the Guardrails (QA) pattern in Tags, such as Guardrail | PII Redaction (did the agent reveal personal data it shouldn’t have?) and Guardrail | Knowledge Restriction Compliance, and assign them to every agent.

4. Escalate clinical questions in the Planning Prompt

The default Escalation Topics in the Planning Prompt’s Knowledge Search – Decision Logic section already include medical emergencies and self-harm. Add your clinical patterns: symptoms, test results, medication questions, and requests on behalf of another person you can’t verify. The planner routes matching conversations to a human and skips knowledge search. See Prompts → Controlling when the agent escalates. For emergency language, add the exact wording your clinical team approves to Main Guidelines → Predefined Replies, so the agent uses it verbatim every time.

5. Route PHI-sensitive intents to an internal note

On Rulebook → Reply Rules:
  • Internal Comment: Clinical or PHI Intent In records_request, proxy_or_caregiver, complaint. The agent drafts; your team verifies and sends.
  • No Reply: Human Agent Assigned Equals True, so the agent never talks over a care coordinator or nurse.
Reply Rules hold only the final reply; Tools in an Intent Rule still run. Don’t put Actions that disclose or change health records in a tree that Internal Comment is meant to hold.

6. Configure guardrails

Confidential attributes is a value-matching check: it blocks replies that contain the values of the attribute keys you select. Guardrails are an extra layer on top of Fini’s automatic masking, which masks sensitive data, including card numbers and health details, everywhere Fini stores conversation data. Guardrails are not a fail-closed security boundary. See Guardrails and Data handling.

7. Identify patients before account-specific answers

Embed the widget in your authenticated patient portal and pass a JWT as customerToken, signed server-side with the widget’s Signing Key (HS256). Include only the identifiers your attribute lookups need in user_attributes, and set collectEmail to false when your portal already verified the email. See Widget → Identify logged-in users. On unauthenticated channels, such as a public website chat or inbound email, limit the agent to general answers from Knowledge and to flows that send information only to contact details already on file (the pattern in Fini for password reset and account access).

8. Give Actions least privilege

  • Credentials Fini uses to call your systems (scheduling, practice management, billing) live in the Data Step Headers of each Attribute and Action. Issue dedicated service credentials: read-only for lookups, and write access limited to the specific endpoints a workflow needs, such as booking or cancelling an appointment.
  • Fini API keys your systems use to call Fini are created under Deploy → API Keys. Uncheck Write for export jobs, use one key per system, and revoke on offboarding. Interaction exports contain conversation content, so treat the systems that receive them as in scope for PHI. See API Keys.

9. Keep knowledge review on

Fini’s background AI and Inbox feedback turn conversations into proposed articles. Leave the workspace “require review” setting on so user-created drafts pass a reviewer in the Review Queue. When you generate an article from an Inbox conversation, choose Suggest for Review rather than Live, which makes the article available immediately. Check each conversation-derived draft for patient details before approving. Background AI drafts always land in review.

10. Run the Test Suite before every publish

Create test cases from conversations with de-identified or synthetic data where you can, and keep them in one collection. Put the shared checks in criteria groups: an AI judgement that the agent declines medical advice, an exact check for the handoff on clinical intents, and exact checks that scheduling Actions run. Test Suite uses recorded or mock Action responses and never calls your APIs; for live end-to-end checks, point Actions at a sandbox environment or run a controlled pilot. See Test Suite.

11. Review in Inbox every week

Filter Inbox by the Guardrail filter under Quality, by your clinical and QA tags, and by Feedback: Thumbs down. Open AI Steps to see each guardrail verdict and every Tool input and output. The Guardrail filter also matches failures recorded in replays of a conversation, so check the replay’s AI Steps before attributing a hit to the live reply.

12. Put dashboard access behind SSO

Fini supports single sign-on with Okta, Google, Slack and Microsoft Entra ID, so dashboard access, and with it access to conversation transcripts, follows your identity provider. The setup guide covers Okta: Okta SSO.

Intents to automate first, and intents to escalate

What to measure

  • AI Resolve Rate per rule in the Analytics Intent rule breakdown, and per tag with the Tags filter. Report Resolved by AI; deflection rate also counts conversations Waiting for Customer.
  • Escalation reasons. On clinical tags, escalation is the intended outcome. On administrative intents, Missing API Access and Missing Knowledge show where to add an Action or article next.
  • Guardrail activity over 7d and 30d, especially the Confidential attributes and no-medical-advice policies. Open every hit.
  • CSAT and sentiment on scheduling and portal-access intents.

End-to-end: cancellation flow

The attribute, Action, rule, and Reply Rules pattern most scheduling flows follow.

HIPAA and BAAs

Fini’s HIPAA compliance and how to put a BAA in place.

Guardrails

Confidential attributes, custom rules, and guardrail activity.

Prompts

Escalation Topics and Predefined Replies.

Attributes

The Use in Rulebooks and Visible to AI switches.

Setting up Fini for fintech and banking

The same checklist for financial services.