Skip to content
Molar AI

Security

Where patient data lives, and who can reach it.

Dental practices are asked to trust a lot of vendors. Here is an accurate account of how Molar handles patient data, including the parts we haven't finished.

01

Your chart stays the source of truth

Molar reads from and writes to your OpenDental. It doesn't ask you to migrate your records into it, and it isn't a replacement chart. What Molar stores is the working state it needs, conversations, form submissions, and the ledger of what was sent.

02

Encryption and isolation

Data is encrypted in transit and at rest. Sensitive submission content, form answers, signatures, uploaded photos, is sealed with its own encryption on top of the database's. Every request is scoped to one practice and one location; there is no query path that returns another practice's data.

03

Access

Staff access is authenticated per user and scoped by location. Patient-facing links, a form request, a booking confirmation, are single-use, expire, and are verified against a second factor the patient knows, such as date of birth. A wrong guess is indistinguishable from a missing link, and repeated attempts lock the link.

04

Messages avoid clinical detail

Text messages pass through carrier infrastructure that we don't control, so message bodies are written to avoid clinical content. The substance stays in Molar and in your chart, behind authentication.

What we haven't done yet.

Being new is not a security property, and a page that only lists strengths isn't worth reading.

  • We are not SOC 2 certified. That audit hasn't been performed.
  • We have not completed a third-party penetration test.
  • There is no such thing as “HIPAA certified” software. We build to HIPAA's requirements and will sign a BAA; anyone claiming certification is describing something that doesn't exist.

Questions we get asked.

Will you sign a BAA?

Yes. Bring it up on the demo call and we'll walk through it.

Where is data hosted?

On AWS, in the United States.

Who at Molar can see our patient data?

Access is limited to what's needed to operate and support the service, and support access is auditable. We don't sell data, and we don't use patient data to train models for anyone else.

Bring your security questions.

Including the awkward ones. You should be asking every vendor these.