Skip to navigation

HIPAA & BAAs

Onboarding required

HIPAA access requires onboarding with Pinnacle and a signed Business Associate Agreement (BAA). Creating an account does not complete onboarding or authorize sending protected health information (PHI).

Contact founders@pinnacle.sh to get started. Before sending PHI:

  1. Complete a BAA with Pinnacle.
  2. Work with Pinnacle to configure your team, phone numbers, credentials, and webhook destinations.
  3. Receive confirmation that your integration is ready for HIPAA use.

Pinnacle provides connection details during onboarding. An existing integration does not move into the HIPAA environment automatically.

Endpoint availability

Expand a group to explore supported endpoints, or select Not supported to browse endpoints in beta. Each operation links to its API reference.

When adapting API examples, use the connection details and credentials provided during HIPAA onboarding. Use synthetic data in the documentation’s API playground.

Fax is a HIPAA-only service that Pinnacle enables during onboarding, including setup for your fax phone numbers. It is not available through the standard API.

Sent and received faxes cost $0.025 per page, regardless of quality. Higher quality settings may take longer to process and send. Before sending a fax, Pinnacle temporarily sets aside enough credits for the prepared document. Afterward, the amount is adjusted to match the pages actually sent. Automatic retries and splitting a large fax into smaller parts do not add extra holds or charges.

Documents must use public HTTPS URLs without credentials. Redirects and private-network URLs are blocked. Files can be up to 50 MB, and a fax can contain 1–3,500 pages. Faxes over 350 pages are automatically split into parts of up to 350 pages each, and every part must be 50 MB or smaller. The parts still appear as one fax in the API.

For readable, reliable faxes:

  • Use high-contrast black text on white Letter or A4 pages. Avoid small print, shading, and color-only meaning; fax transmission can change their appearance.
  • Preview each source page before sending. Pinnacle fits TIFF pages to US Letter while preserving their aspect ratio, but fax transmission can still blur fine detail.
  • Confirm the final status and transmitted page count. For important information, review the received pages with the recipient; neither an accepted request nor a page count proves legibility.

Pinnacle checks each document before sending it and rejects unsafe, damaged, encrypted, or oversized files. Rejected files fail before any credits are set aside. See Send Fax for all document and duplicate-request requirements.

Fax webhooks do not include document URLs. When you receive a FAX.RECEIVED event, call Get Fax with fax.id. The authenticated response includes a signed mediaUrl that expires after one hour. Treat this URL as sensitive: do not log or store it, and request a new one after it expires.

MethodEndpointAPI reference
POST/faxSend Fax
GET/faxList Faxes
GET/fax/{id}Get Fax
POST/fax/{id}/cancelCancel Fax
MethodEndpointAPI reference
POST/messages/listList Messages
GET/messages/{id}Get Message by ID
POST/messages/send/smsSend SMS Message
POST/messages/send/mmsSend MMS Message
POST/messages/reactReact to a Message
POST/messages/blast/smsBlast SMS to Audience
POST/messages/blast/mmsBlast MMS to Audience
POST/messages/validate/smsValidate SMS Message
POST/messages/validate/mmsValidate MMS Message
DELETE/messages/schedule/{id}Cancel Scheduled Message
POST/messages/schedules/listList Scheduled Messages
POST/messages/blasts/listList Blasts
MethodEndpointAPI reference
POST/conversations/listList Conversations
POST/conversations/getGet Conversation
POST/conversations/updateUpdate Conversation
POST/conversations/{id}/messagesList Conversation Messages
MethodEndpointAPI reference
POST/contacts/listList Contacts
GET/contactsGet Contact
POST/contactsCreate New Contact
PUT/contactsUpdate Contact
MethodEndpointAPI reference
POST/audiences/listList Audiences
GET/audiencesGet Audience
POST/audiencesCreate Audience
PATCH/audiencesUpdate Audience
DELETE/audiencesDelete Audience
PATCH/audiences/contactsAdd Contacts to Audience
DELETE/audiences/contactsRemove Contacts from Audience
MethodEndpointAPI reference
POST/tools/files/uploadUpload File
POST/tools/files/refreshRefresh File URLs
POST/tools/contact-cardGet Contact Card
POST/tools/contact-card/upsertUpsert Contact Card
MethodEndpointAPI reference
POST/webhooks/listList Webhooks
POST/webhooksRetrieve Webhooks
POST/webhooks/attachAttach Webhook
POST/webhooks/detachDetach Webhook
MethodEndpointAPI reference
POST/phone-numbers/listList Phone Numbers
POST/phone-numbers/searchSearch for Available Phone Numbers
POST/phone-numbers/buyBuy Phone Numbers
POST/phone-numbers/attach-campaignAttach Campaign
DELETE/phone-numbers/detach-campaignDetach Campaign
MethodEndpointAPI reference
POST/brands/listList Brands
GET/brands/{id}Get Brand by ID
POST/brandsCreate or Update a Brand
POST/brands/{brandId}/submitSubmit Brand
POST/brands/{brandId}/vetVet Brand
POST/brands/autofillAutofill Brand Information
POST/brands/validateValidate Brand Information
MethodEndpointAPI reference
POST/campaigns/dlc/listList 10DLC Campaigns
GET/campaigns/dlc/{campaignId}Get 10DLC Campaign by ID
POST/campaigns/dlcCreate or Update 10DLC Campaign
POST/campaigns/dlc/submit/{campaignId}Submit 10DLC Campaign
POST/campaigns/dlc/autofillAutofill 10DLC Campaign Information
POST/campaigns/dlc/validateValidate 10DLC Campaign Information
MethodEndpointAPI reference
POST/campaigns/toll-free/listList Toll-Free Campaigns
GET/campaigns/toll-free/{campaignId}Get Toll-Free Campaign by ID
POST/campaigns/toll-freeCreate or Update Toll-Free Campaign
POST/campaigns/toll-free/submit/{campaignId}Submit Toll-Free Campaign
POST/campaigns/toll-free/autofillAutofill Toll-Free Campaign Information
POST/campaigns/toll-free/validateValidate Toll-Free Campaign Information
MethodEndpointAPI reference
GET/status/brand/{brandId}Get Brand Status
GET/status/dlc-campaign/{campaignId}Get 10DLC Campaign Status
GET/status/toll-free-campaign/{campaignId}Get Toll-Free Campaign Status
GET/status/phone-number/{phoneNumber}Get Phone Number Status

Handling patient information

Keep patient information out of support requests, documentation tools, brand and campaign registration, and autofill inputs. Limit access to webhook payloads, message responses, and media links to authorized people and systems.