
Doxy.me typical implementation process:
Account Registration: Providers begin by signing up on the Doxy.me website, selecting “I’m a Provider”, and creating a personalized telehealth room name. This step takes only a few minutes and establishes their secure, browser‑based virtual clinic.
Setting Up the Virtual Room: Once logged in, users can configure their virtual waiting room, add clinic logos, custom text, or videos, and enable notifications. Providers verify their Business Associate Agreement (BAA) and update security preferences to ensure compliance.
System Preparation: The next step involves checking hardware (camera, microphone, and internet), testing browser permissions (Chrome, Firefox, Safari), and ensuring HIPAA‑compliant call functionality. Clinics may also configure secondary tools like e‑fax or VoIP systems, depending on workflow.
Clinic Upgrade and Branding: For multi‑provider offices, upgrading to the Clinic plan activates centralized management, user permissions, and sub‑domain branding. The onboarding team collects brand assets to design a customized clinic portal.
Workflow Customization: Providers set up schedules, assign patient URLs, and test out waiting room queue management and teleconsent workflows. This ensures uniform appointment handling across clinicians.
Integration Setup (Optional): Clinics can connect Doxy.me to their EHR or PMS, such as Epic or Juvonno, by embedding unique provider room URLs or using the integration module in the partner system.
Testing and Staff Training: Teams run internal test calls with staff and patients to confirm performance across devices, teach troubleshooting basics, and practice live‑chat and file‑sharing processes.
Doxy.me offers extensive customization for solo providers and multi‑clinic organizations, enabling branded experiences, workflow tailoring, and optional integrations while preserving its no‑download, browser‑based simplicity.
Branded virtual rooms: Providers can customize their virtual waiting rooms with clinic logos, colors, background images, welcome text, videos, and links, creating a consistent, patient‑facing brand experience without custom code.
Personalized URLs and subdomains: Each clinician receives a unique room link; the clinic plans can provision branded subdomains and shared rooms to standardize the access experience across teams and departments.
Waiting room content control: Clinics can add intake instructions, house rules, FAQs, or pre‑visit forms in the waiting room to reduce admin time and guide patients before sessions begin.
Queue and workflow configuration: The patient queue can be configured to match front‑desk workflows (transfer between rooms, hold, notify, prioritize) so larger teams can manage concurrent sessions efficiently.
Teleconsent templates: Built‑in teleconsent enables clinics to standardize consent language and capture e‑signatures consistently, aligning with specialty‑specific requirements and risk policies.
Multi‑provider clinic controls: The Clinic tier adds centralized admin for user provisioning, role‑based access, shared or provider‑specific rooms, and organization‑wide branding to keep experiences consistent across locations.
Configurable notifications: Providers can tailor patient invites and reminders (email/SMS), including custom copy and timing, to fit clinic communication policies and reduce no‑shows.
Payment customization: Integrated payments can be enabled per provider or clinic with options to request payments before, during, or after the visit, supporting different financial workflows and visit types.
Language and accessibility: Doxy.me supports multiple languages and is optimized for common browsers and devices, allowing clinics to adapt patient instructions and UX for diverse populations without separate apps.
Security policy alignment: Clinics can align configurations with HIPAA, GDPR, PHIPA/PIPEDA, and HITECH standards; every plan includes a free BAA, and SOC 2/SOC 3 attestations support enterprise compliance programs.
Integration pathways: Doxy.me supports embedding room links into EHR/PMS systems and offers API/webhook patterns to coordinate check‑ins, documentation triggers, and post‑visit workflows with external tools.
EHR/PMS embeddings: Documented connections exist with systems like Nookal and Juvonno, enabling appointment handoffs, provider‑room linking, and consistent visit flows from the scheduling system to the video room.
AI scribe and intake add‑ons: Clinics can extend functionality with AI scribes (e.g., automated SOAP note drafting) and Dokbot conversational intake to standardize pre‑visit data capture and accelerate documentation.
Role‑specific experiences: Clinician, scheduler, and supervisor views can be organized to reflect job duties, enabling dedicated dashboards and permissions for clinical versus administrative staff.
Group visit configuration: Providers can enable group sessions (e.g., up to 25 participants) and customize waiting room messaging and facilitation protocols for classes, group therapy, or education.
Analytics and reporting: Clinics can tailor dashboards and usage analytics to track wait times, utilization, and provider activity, supporting operational KPIs and quality initiatives.
Device and bandwidth optimization: Adaptive video and audio settings help clinics standardize call quality targets and support lower‑bandwidth patient scenarios without separate software builds.
Patient experience assets: Custom pre‑visit checklists, troubleshooting links, and branding elements reduce support load and create consistent experiences across service lines.
Doxy.me provides a strong support and training framework to help new users — from solo providers to multi‑clinic teams — get onboarded, adopt best telemedicine practices, and stay supported long‑term. Its model combines self‑service learning, webinars, and responsive live support for a quick start and continuous learning.
Step‑by‑step onboarding: New users are guided through account setup, branding, and waiting room customization using the Getting Started tutorial series. This includes video walkthroughs, checklists, and test call simulations for both patient and provider experiences.
Help Center and knowledge base: The Doxy.me Help Center hosts 300+ detailed articles, FAQs, and troubleshooting guides. Each section covers setup, clinic upgrades, security management, and new feature releases updated monthly.
Live webinars: Doxy.me runs complimentary 45‑minute Live Webinars weekly via the Demio platform, covering telehealth best practices, new features, and workflow optimization. Participants gain access to webinar handouts and recordings afterward. Attendees even receive a free trial upgrade upon completion.
Hands‑on practice mode: The platform includes a Practice Call feature that allows providers to simulate a session and test features such as video, file sharing, and chat without connecting to a real patient.
Technical and clinical workflow support: For immediate assistance, users can click the Help button on their Doxy.me dashboard to chat directly with the Support Desk. Issues are triaged instantly to the relevant team, and higher‑tier plans include priority support and faster resolution timelines.
Toolkits and success resources: Doxy.me publishes a Launch Success Kit and Telehealth Mastery Series in its “Mastering Telemedicine” section, which provides downloadable guides and short video lessons for improving digital bedside manner and managing hybrid telemedicine models.
Peer‑supported learning: In collaboration with regional initiatives such as the Doctors Technology Office Peer Mentor Program, providers can join telehealth mentorship networks for direct, peer‑to‑peer support and advanced learning opportunities.
Ongoing updates and continuous education: New product features are documented through monthly “What’s New” updates with video demos and articles explaining enhancements like file transfer, teleconsent, analytics, and AI‑driven scribe tools.
Doxy.me employs multiple layers of technical, administrative, and physical safeguards to ensure healthcare data confidentiality, integrity, and availability, meeting U.S. and international security standards such as HIPAA, HITECH, GDPR, PHIPA/PIPEDA, and SOC 2 Type II. Its architecture is designed specifically for telehealth, offering secure streaming, zero PHI storage, and industry‑grade encryption hosted on Amazon Web Services (AWS).
End‑to‑end encryption: All video, audio, and chat communications are transmitted via WebRTC point‑to‑point AES‑128 encryption, protecting sessions end to end. Data stored at rest, such as logs or configuration data, is protected with AES‑256 full‑volume encryption using AWS FIPS 140‑2–certified key management and hardware security modules.
Zero data retention: Doxy.me does not record or store any video, audio, or chat content on its servers. This “data‑lean” model minimizes breach risk and supports HIPAA’s minimum necessary principle.
SOC 2 Type II and SOC 3 certifications: Independent auditors at BARR Advisory verify that Doxy.me maintains effective controls across security, confidentiality, and availability. About 160 controls covering access management, HR vetting, encryption, and system monitoring were tested during its latest cycle.
HIPAA compliance program: Doxy.me maintains a formal HIPAA Security Officer, conducts annual HIPAA risk assessments, third‑party penetration testing, and continuous vulnerability scanning. Staff and contractors undergo mandatory HIPAA and security training with confidentiality agreements. Risk reports drive policy updates each assessment cycle.
AWS secure hosting: All infrastructure runs within hardened AWS environments featuring physical data center security, redundant storage, and environmental controls. Doxy.me adds IDS/IPS monitoring, file integrity validation, and root process checks through OSSEC‑based agents to detect and block intrusion attempts in real time.
Password and access security: Provider credentials use one‑way cryptographic hashing; even system administrators cannot retrieve them. Strong password enforcement and multifactor authentication through Google, Facebook, or SAML/LDAP (for Clinic plans) provide enhanced access control.
TLS and HTTPS encryption: Every webpage, dashboard, and waiting room operates under TLS 1.2+, ensuring encrypted connections and preventing interception during login or data transit.
FIPS 140‑2 validated cryptography: Doxy.me’s AWS Key Management System and associated Hardware Security Modules are NIST‑validated for Levels 2–3 assurance, meeting U.S. government‑grade cryptographic standards.
Compliance transparency and BAA: Every plan—from Free to Enterprise—includes a free Business Associate Agreement, ensuring legal coverage for U.S. healthcare entities handling PHI. The company further aligns with GDPR’s Article 28 processor obligations and offers opt‑in custom terms of service for EU clients during patient check‑in.
Incident response and breach notification: Doxy.me keeps documented procedures compliant with the HIPAA Breach Notification Rule; any attempt to access or alter data triggers internal alerts, immediate containment, and investigation protocols.
Doxy.me ships updates on a frequent, cloud‑managed cadence with public “What’s new” posts summarizing feature changes and fixes each month, alongside periodic seasonal releases (e.g., Spring 2025 Apps launch) that bundle larger enhancements to the dashboard, video experience, and clinic tools. These releases are applied automatically to all accounts with no software installs, and are accompanied by help-center articles, preview environments, and webinars to ease adoption.
Update frequency and scope: Monthly release notes highlight iterative improvements such as closed captions, background‑noise reduction, Apple Pay in Payments, Timer and Transcript Apps, and group‑call upgrades; larger quarterly/seasonal drops introduce broader UX and workflow changes across Dashboard, Waiting Room, and Video Call.
Cloud delivery and zero‑install: As a browser‑based SaaS, updates roll out centrally and require no downloads or patches; providers see new capabilities on next login, with in‑app cues and “Launch Success Kit” guides detailing changes and how to use them.
Status and maintenance communications: A public status page announces incidents and planned maintenance windows, with incident histories and real‑time notices when third‑party infrastructure (e.g., AWS) affects performance; clinics can subscribe for alerts.
Doxy.me’s policy ensures that clinics and healthcare providers retain full ownership and control over their patient data, while Doxy.me acts solely as a secure processor and facilitator in line with HIPAA and GDPR requirements. Providers are responsible for creating, managing, and exporting data, and Doxy.me’s design further supports data portability and downstream continuity for practices of any size.
Data ownership: All protected health information (PHI), clinical documentation, patient metadata, and meeting histories generated using Doxy.me belong exclusively to the provider or health organization. Doxy.me maintains no proprietary claim over customer-uploaded or recorded data, ensuring that clinics remain the controllers for compliance, retention, and deletion decisions.
Zero PHI storage: Doxy.me’s core platform is architected not to record, persist, or retain any video, audio, or chat content. Only minimal session logs, configuration data, or operational analytics—devoid of patient identifiers or PHI—are stored on secure, encrypted servers, in accordance with the platform’s “data-lean” privacy model.
Data portability: Providers can export patient lists, appointment records, meeting histories, and relevant communications as needed, particularly within the Clinic and Enterprise plans. Export formats such as CSV or XLS are available for bulk downloads, enabling smooth data migration to EHR, CRM, or other healthcare systems without vendor lock-in.
Compliance alignment: Doxy.me’s privacy and security framework supports the right of data subjects to access, correct, and transfer their personal data as dictated by HIPAA, HITECH, GDPR, and PHIPA/PIPEDA. For clinics serving international populations, Doxy.me aligns with Article 20 of GDPR (right to data portability) and Article 15 (right of access), facilitating patient data subject requests through designated provider processes.
Post-termination policy: Partner organizations are advised to utilize available export tools and download all necessary data before terminating accounts. Upon termination, any remaining operational data is purged from Doxy.me’s servers in accordance with established retention and disposal policies.
Doxy.me provides flexible, self-managed terms for scaling up or down subscription plans as an organization’s size or usage needs change. Its billing model and user management tools allow clinics to add or remove providers, switch plan tiers, or downgrade to free access without major administrative overhead.
Plan upgrades: Users can upgrade from Free to Professional or Clinic plans at any time by selecting Upgrade in the dashboard and confirming payment details. Upgrades take effect immediately, unlocking advanced features such as group calling, teleconsent, and custom branding for clinics.
Adding users and licenses: Doxy.me uses a seat-based licensing system, where each active provider requires a paid license. Clinics can add or remove seats (licenses) directly within Account Settings → Clinic Settings → Manage Users → Add or remove paid seats. Billing is prorated for additional users added mid-cycle. For example, increasing from 10 to 12 users updates the total licenses accordingly.
Removing users or reducing seats: Removing a user does not automatically reduce billing charges. Administrators must manually lower the seat count before the next billing period to avoid continued billing for unused accounts. Adjustments only take effect at the start of the next renewal period.
Downgrading plans: Providers can downgrade to the Free Plan at any time. Once a downgrade is processed, paid features remain available until the end of the billing cycle. For Clinic plans, only the account owner can initiate the downgrade by contacting Doxy.me support under Help → Billing → Cancel/Pause Subscription.
Billing adjustments and refunds: Doxy.me operates a strict no-refund policy for cancellations or downgrades made mid-cycle. Unused time within the current billing period is forfeited, though the paid features remain active until the term ends. If subscription changes are made mid-cycle, previously paid amounts are credited toward the new plan.
Scaling to enterprise level: Organizations requiring large-scale telehealth implementations can request customized Enterprise Agreements that include bulk license management, volume pricing, SSO/LDAP integration, and account-level support. Contracts can scale dynamically through Doxy.me’s AWS-backed infrastructure without service disruption.
License and seat flexibility: Doxy.me’s cloud-based model enables organizations to scale in real time — adding providers during high-demand periods (such as seasonal surges) and reducing seats during slower months, ensuring cost efficiency while maintaining continuous access.
Technical scalability: Doxy.me’s AWS infrastructure supports elastic scaling, meaning the platform’s backend resources automatically adjust with user traffic. This ensures enterprise clients and high-volume clinics remain fully operational during sudden demand spikes or expansions.
Doxy.me’s terms for contract renewal and cancellation are straightforward, highly transparent, and designed to offer flexibility for both individual practitioners and clinics. Subscriptions renew automatically unless manually canceled by the user in account settings, and cancellations are processed to take effect at the end of the current billing cycle. Below are the detailed policy points based on the platform’s current documentation and support articles.
Automatic renewal: All paid Doxy.me subscriptions (Professional, Clinic, and Enterprise) automatically renew on a monthly or annual basis, depending on the chosen billing frequency. Payment is required in full at the start of each renewal term.
Cancellation process: Users can cancel at any time through the Account Settings → Billing section of the dashboard. Cancellation prevents auto‑renewal, allowing continued use of paid features until the end of the current billing term. The account then automatically converts to the free plan, which retains basic telehealth functionality.
Clinic plan cancellations: For multi‑provider Clinic accounts, only the account owner or administrator can initiate cancellation. This is done by contacting support through the in‑app Help → Billing → Cancel/Pause Subscription workflow. A confirmation message is sent once the cancellation is complete.
Refund policy: Doxy.me enforces a strict no‑refund policy. Payments for unused time, early cancellations, downgrades, or removal of users before renewal are non‑refundable. Administrators are advised to review license quantities before renewal to avoid being billed for inactive accounts. Payments remain valid throughout the paid period even if the plan is canceled mid‑term.
Early cancellation exceptions: While refunds are generally not permitted, special cases such as billing errors or system malfunctions can be reviewed manually by the support team. Refund requests are evaluated on a case‑by‑case basis, but are not guaranteed approval.
License management and seat adjustments: Removing a user does not automatically reduce billed licenses. Clinics must manually adjust their license count in settings before renewal; otherwise, charges for existing seats continue even if those users are inactive.
Downgrade to free plan: Professional users may choose to revert to the Free Plan at any time. The downgrade takes effect after the current term ends, retaining access to paid features until expiration without further billing.
Billing, taxes, and exemptions: Doxy.me automatically applies regional sales tax or VAT where required by law. Customers with tax‑exempt status can submit valid exemption documentation to have taxes refunded or credited within 10–15 businessdays.
Failure to pay: If subscription payments are missed or declined, Doxy.me reserves the right to suspend or revoke account access until outstanding balances are paid in full. Unpaid accounts may eventually be terminated after notice.
Account deletion and data removal: Upon account termination, users can permanently delete their data via the Account Settings → Delete Account option. Once deleted, data cannot be recovered, ensuring compliance with privacy regulations such as GDPR and HIPAA.
Doxy.me meets a set of compliance standards that make it one of the most trusted telemedicine platforms globally for secure and lawful virtual healthcare delivery. Its framework is designed for both U.S. and international providers, ensuring robust data protection and privacy for every session.
HIPAA Compliance: Doxy.me is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA), including the Security and Privacy Rules for handling PHI. This includes end-to-end encryption, audit controls, role-based access, and secure hosting—all reinforced by a free Business Associate Agreement (BAA) included in every plan.
HITECH Act: The platform is aligned with HITECH Act requirements for electronic health records (EHR) access, auditability, breach notification, and secure health information exchange.
GDPR Compliance: Doxy.me is General Data Protection Regulation (GDPR)-compliant for users in the EU, with processes to support patient rights to access, portability, correction, and deletion of data. It operates as a GDPR Article 28 processor and uses data minimization by default.
PHIPA/PIPEDA Compliance: The platform supports Canadian privacy and security rules, including PHIPA (Ontario) and PIPEDA (federal), giving confidence to clinics and providers serving Canadian patients.
SOC 2 Type II and SOC 3 Certification: Doxy.me has undergone independent audits by BARR Advisory (SOC 2 Type II and SOC 3), confirming controls for security, availability, confidentiality, and privacy across its cloud operation.
End-to-End Encryption: Every call, chat, and file transfer is protected by industry-standard encryption (WebRTC with AES-128 in transit and AES-256 at rest), compliant with FIPS 140-2 requirements for government-grade cryptography.