HIPAA & BAAs
Onboarding required
HIPAA access requires onboarding with Pinnacle and a signed Business Associate Agreement (BAA). Creating an account does not complete onboarding or authorize sending protected health information (PHI).
Contact founders@pinnacle.sh to get started. Before sending PHI:
- Complete a BAA with Pinnacle.
- Work with Pinnacle to configure your team, phone numbers, credentials, and webhook destinations.
- Receive confirmation that your integration is ready for HIPAA use.
Pinnacle provides connection details during onboarding. An existing integration does not move into the HIPAA environment automatically.
Endpoint availability
Expand a group to explore supported endpoints, or select Not supported to browse endpoints in beta. Each operation links to its API reference.
When adapting API examples, use the connection details and credentials provided during HIPAA onboarding. Use synthetic data in the documentation’s API playground.
Supported (67)
Not supported (32)
Fax ✓ HIPAA only
Fax is a HIPAA-only service that Pinnacle enables during onboarding, including setup for your fax phone numbers. It is not available through the standard API.
Sent and received faxes cost $0.025 per page, regardless of quality. Higher quality settings may take longer to process and send. Before sending a fax, Pinnacle temporarily sets aside enough credits for the prepared document. Afterward, the amount is adjusted to match the pages actually sent. Automatic retries and splitting a large fax into smaller parts do not add extra holds or charges.
Documents must use public HTTPS URLs without credentials. Redirects and private-network URLs are blocked. Files can be up to 50 MB, and a fax can contain 1–3,500 pages. Faxes over 350 pages are automatically split into parts of up to 350 pages each, and every part must be 50 MB or smaller. The parts still appear as one fax in the API.
For readable, reliable faxes:
- Use high-contrast black text on white Letter or A4 pages. Avoid small print, shading, and color-only meaning; fax transmission can change their appearance.
- Preview each source page before sending. Pinnacle fits TIFF pages to US Letter while preserving their aspect ratio, but fax transmission can still blur fine detail.
- Confirm the final status and transmitted page count. For important information, review the received pages with the recipient; neither an accepted request nor a page count proves legibility.
Pinnacle checks each document before sending it and rejects unsafe, damaged, encrypted, or oversized files. Rejected files fail before any credits are set aside. See Send Fax for all document and duplicate-request requirements.
Fax webhooks do not include document URLs. When you receive a FAX.RECEIVED event, call Get Fax with fax.id. The authenticated response includes a signed mediaUrl that expires after one hour. Treat this URL as sensitive: do not log or store it, and request a new one after it expires.
Messages 12 of 17 supported
Conversations ✓ All supported
Contacts ✓ All supported
Audiences ✓ All supported
Files and contact cards ✓ All supported
Webhooks ✓ All supported
Phone Numbers 5 of 6 supported
Brands ✓ All supported
Campaigns / 10DLC ✓ All supported
Campaigns / Toll-Free ✓ All supported
Status 4 of 5 supported
Handling patient information
Keep patient information out of support requests, documentation tools, brand and campaign registration, and autofill inputs. Limit access to webhook payloads, message responses, and media links to authorized people and systems.

