> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.pinnacle.sh/v-2/documentation/hipaa/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.pinnacle.sh/_mcp/server. # HIPAA & BAAs > Arrange HIPAA onboarding with Pinnacle and check which API endpoints are supported or unavailable. ## Onboarding required > **Note** > > **HIPAA access requires onboarding with Pinnacle and a signed Business Associate Agreement (BAA).** Creating an account does not complete onboarding or authorize sending protected health information (PHI). Contact [founders@pinnacle.sh](mailto:founders@pinnacle.sh) to get started. Before sending PHI: 1. Complete a BAA with Pinnacle. 2. Work with Pinnacle to configure your team, phone numbers, credentials, and webhook destinations. 3. Receive confirmation that your integration is ready for HIPAA use. Pinnacle provides connection details during onboarding. An existing integration does not move into the HIPAA environment automatically. ## Endpoint availability Expand a group to explore supported endpoints, or select Not supported to browse endpoints in beta. Each operation links to its API reference. > **Warning** > > When adapting API examples, use the connection details and credentials provided during HIPAA onboarding. Use synthetic data in the documentation's API playground. #### Supported (67) #### Fax ✓ HIPAA only Fax is a HIPAA-only service that Pinnacle enables during onboarding, including setup for your fax phone numbers. It is not available through the standard API. Sent and received faxes cost **\$0.025 per page**, regardless of quality. Higher quality settings may take longer to process and send. Before sending a fax, Pinnacle temporarily sets aside enough credits for the prepared document. Afterward, the amount is adjusted to match the pages actually sent. Automatic retries and splitting a large fax into smaller parts do not add extra holds or charges. Documents must use public HTTPS URLs without credentials. Redirects and private-network URLs are blocked. Files can be up to 50 MB, and a fax can contain 1–3,500 pages. Faxes over 350 pages are automatically split into parts of up to 350 pages each, and every part must be 50 MB or smaller. The parts still appear as one fax in the API. For readable, reliable faxes: * Use high-contrast black text on white Letter or A4 pages. Avoid small print, shading, and color-only meaning; fax transmission can change their appearance. * Preview each source page before sending. Pinnacle fits TIFF pages to US Letter while preserving their aspect ratio, but fax transmission can still blur fine detail. * Confirm the final status and transmitted page count. For important information, review the received pages with the recipient; neither an accepted request nor a page count proves legibility. Pinnacle checks each document before sending it and rejects unsafe, damaged, encrypted, or oversized files. Rejected files fail before any credits are set aside. See [Send Fax](/api-reference/fax-hipaa-only/send) for all document and duplicate-request requirements. Fax webhooks do not include document URLs. When you receive a `FAX.RECEIVED` event, call [Get Fax](/api-reference/fax-hipaa-only/get) with `fax.id`. The authenticated response includes a signed `mediaUrl` that expires after one hour. Treat this URL as sensitive: do not log or store it, and request a new one after it expires.
Method Endpoint API reference
`POST` `/fax` [Send Fax](/api-reference/fax-hipaa-only/send)
`GET` `/fax` [List Faxes](/api-reference/fax-hipaa-only/list)
`GET` `/fax/{id}` [Get Fax](/api-reference/fax-hipaa-only/get)
`POST` `/fax/{id}/cancel` [Cancel Fax](/api-reference/fax-hipaa-only/cancel)
#### Messages 12 of 17 supported
Method Endpoint API reference
`POST` `/messages/list` [List Messages](/api-reference/messages/list)
`GET` `/messages/{id}` [Get Message by ID](/api-reference/messages/get)
`POST` `/messages/send/sms` [Send SMS Message](/api-reference/messages/send-sms)
`POST` `/messages/send/mms` [Send MMS Message](/api-reference/messages/send-mms)
`POST` `/messages/react` [React to a Message](/api-reference/messages/react)
`POST` `/messages/blast/sms` [Blast SMS to Audience](/api-reference/messages/blast-sms)
`POST` `/messages/blast/mms` [Blast MMS to Audience](/api-reference/messages/blast-mms)
`POST` `/messages/validate/sms` [Validate SMS Message](/api-reference/messages/validate-sms)
`POST` `/messages/validate/mms` [Validate MMS Message](/api-reference/messages/validate-mms)
`DELETE` `/messages/schedule/{id}` [Cancel Scheduled Message](/api-reference/messages/cancel-scheduled-message)
`POST` `/messages/schedules/list` [List Scheduled Messages](/api-reference/messages/list-scheduled-messages)
`POST` `/messages/blasts/list` [List Blasts](/api-reference/messages/list-blasts)
#### Conversations ✓ All supported
Method Endpoint API reference
`POST` `/conversations/list` [List Conversations](/api-reference/conversations/list)
`POST` `/conversations/get` [Get Conversation](/api-reference/conversations/get)
`POST` `/conversations/update` [Update Conversation](/api-reference/conversations/update)
`POST` `/conversations/{id}/messages` [List Conversation Messages](/api-reference/conversations/list-messages)
#### Contacts ✓ All supported
Method Endpoint API reference
`POST` `/contacts/list` [List Contacts](/api-reference/contacts/list)
`GET` `/contacts` [Get Contact](/api-reference/contacts/get)
`POST` `/contacts` [Create New Contact](/api-reference/contacts/create)
`PUT` `/contacts` [Update Contact](/api-reference/contacts/update)
#### Audiences ✓ All supported
Method Endpoint API reference
`POST` `/audiences/list` [List Audiences](/api-reference/audiences/list)
`GET` `/audiences` [Get Audience](/api-reference/audiences/get)
`POST` `/audiences` [Create Audience](/api-reference/audiences/create)
`PATCH` `/audiences` [Update Audience](/api-reference/audiences/update)
`DELETE` `/audiences` [Delete Audience](/api-reference/audiences/delete)
`PATCH` `/audiences/contacts` [Add Contacts to Audience](/api-reference/audiences/add-contacts)
`DELETE` `/audiences/contacts` [Remove Contacts from Audience](/api-reference/audiences/remove-contacts)
#### Files and contact cards ✓ All supported
Method Endpoint API reference
`POST` `/tools/files/upload` [Upload File](/api-reference/tools/upload-file)
`POST` `/tools/files/refresh` [Refresh File URLs](/api-reference/tools/refresh-file)
`POST` `/tools/contact-card` [Get Contact Card](/api-reference/tools/get-contact-card)
`POST` `/tools/contact-card/upsert` [Upsert Contact Card](/api-reference/tools/upsert-contact-card)
#### Webhooks ✓ All supported
Method Endpoint API reference
`POST` `/webhooks/list` [List Webhooks](/api-reference/webhooks/list)
`POST` `/webhooks` [Retrieve Webhooks](/api-reference/webhooks/get)
`POST` `/webhooks/attach` [Attach Webhook](/api-reference/webhooks/attach-webhook)
`POST` `/webhooks/detach` [Detach Webhook](/api-reference/webhooks/detach-webhook)
#### Phone Numbers 5 of 6 supported
Method Endpoint API reference
`POST` `/phone-numbers/list` [List Phone Numbers](/api-reference/phone-numbers/list)
`POST` `/phone-numbers/search` [Search for Available Phone Numbers](/api-reference/phone-numbers/search)
`POST` `/phone-numbers/buy` [Buy Phone Numbers](/api-reference/phone-numbers/buy)
`POST` `/phone-numbers/attach-campaign` [Attach Campaign](/api-reference/phone-numbers/attach-campaign)
`DELETE` `/phone-numbers/detach-campaign` [Detach Campaign](/api-reference/phone-numbers/detach-campaign)
#### Brands ✓ All supported
Method Endpoint API reference
`POST` `/brands/list` [List Brands](/api-reference/brands/list)
`GET` `/brands/{id}` [Get Brand by ID](/api-reference/brands/get)
`POST` `/brands` [Create or Update a Brand](/api-reference/brands/upsert)
`POST` `/brands/{brandId}/submit` [Submit Brand](/api-reference/brands/submit)
`POST` `/brands/{brandId}/vet` [Vet Brand](/api-reference/brands/vet)
`POST` `/brands/autofill` [Autofill Brand Information](/api-reference/brands/autofill)
`POST` `/brands/validate` [Validate Brand Information](/api-reference/brands/validate)
#### Campaigns / 10DLC ✓ All supported
Method Endpoint API reference
`POST` `/campaigns/dlc/list` [List 10DLC Campaigns](/api-reference/campaigns/10-dlc/list)
`GET` `/campaigns/dlc/{campaignId}` [Get 10DLC Campaign by ID](/api-reference/campaigns/10-dlc/get)
`POST` `/campaigns/dlc` [Create or Update 10DLC Campaign](/api-reference/campaigns/10-dlc/upsert)
`POST` `/campaigns/dlc/submit/{campaignId}` [Submit 10DLC Campaign](/api-reference/campaigns/10-dlc/submit)
`POST` `/campaigns/dlc/autofill` [Autofill 10DLC Campaign Information](/api-reference/campaigns/10-dlc/autofill)
`POST` `/campaigns/dlc/validate` [Validate 10DLC Campaign Information](/api-reference/campaigns/10-dlc/validate)
#### Campaigns / Toll-Free ✓ All supported
Method Endpoint API reference
`POST` `/campaigns/toll-free/list` [List Toll-Free Campaigns](/api-reference/campaigns/toll-free/list)
`GET` `/campaigns/toll-free/{campaignId}` [Get Toll-Free Campaign by ID](/api-reference/campaigns/toll-free/get)
`POST` `/campaigns/toll-free` [Create or Update Toll-Free Campaign](/api-reference/campaigns/toll-free/upsert)
`POST` `/campaigns/toll-free/submit/{campaignId}` [Submit Toll-Free Campaign](/api-reference/campaigns/toll-free/submit)
`POST` `/campaigns/toll-free/autofill` [Autofill Toll-Free Campaign Information](/api-reference/campaigns/toll-free/autofill)
`POST` `/campaigns/toll-free/validate` [Validate Toll-Free Campaign Information](/api-reference/campaigns/toll-free/validate)
#### Status 4 of 5 supported
Method Endpoint API reference
`GET` `/status/brand/{brandId}` [Get Brand Status](/api-reference/status/brand)
`GET` `/status/dlc-campaign/{campaignId}` [Get 10DLC Campaign Status](/api-reference/status/dlc-campaign)
`GET` `/status/toll-free-campaign/{campaignId}` [Get Toll-Free Campaign Status](/api-reference/status/toll-free-campaign)
`GET` `/status/phone-number/{phoneNumber}` [Get Phone Number Status](/api-reference/status/phone-number)
#### Not supported (32) HIPAA support for these endpoints is in beta and requires separate approval. If your integration needs any of them, [contact Pinnacle](mailto:founders@pinnacle.sh) to discuss access. Do not send PHI through these endpoints until Pinnacle confirms support for your integration. #### RCS messages and simulated events (5) | Method | Endpoint | API reference | | ------ | ------------------------- | -------------------------------------------------------------------- | | `POST` | `/messages/send/rcs` | [Send RCS Message](/api-reference/messages/send-rcs) | | `POST` | `/messages/send/typing` | [Send Typing Indicator](/api-reference/messages/send-typing) | | `POST` | `/messages/blast/rcs` | [Blast RCS to Audience](/api-reference/messages/blast-rcs) | | `POST` | `/messages/validate/rcs` | [Validate RCS Message](/api-reference/messages/validate-rcs) | | `POST` | `/messages/simulate/user` | [Simulate Inbound User Event](/api-reference/messages/simulate-user) | #### RCS agents and testing (9) | Method | Endpoint | API reference | | ------- | -------------------------------------- | ---------------------------------------------------------------------------------- | | `GET` | `/rcs/{agentId}` | [Get Agent](/api-reference/rcs-agents/get-agent) | | `POST` | `/rcs/agents/list` | [List RCS Agents](/api-reference/rcs-agents/list) | | `POST` | `/rcs/test/numbers/list` | [List Whitelisted Numbers](/api-reference/rcs-agents/list-whitelisted-numbers) | | `POST` | `/rcs/capabilities` | [Get RCS Capabilities](/api-reference/rcs-agents/get-capabilities) | | `POST` | `/rcs/link` | [Generate RCS Link](/api-reference/rcs-agents/get-link) | | `POST` | `/rcs/test/agents` | [Create Test Agent](/api-reference/rcs-agents/test/create-agent) | | `PATCH` | `/rcs/test/agents/{agentId}` | [Update Test Agent](/api-reference/rcs-agents/test/update-agent) | | `POST` | `/rcs/test/agents/{agentId}/whitelist` | [Whitelist Number for Test Agent](/api-reference/rcs-agents/test/whitelist-number) | | `GET` | `/rcs/test/agents/{agentId}/numbers` | [Get Whitelist Status](/api-reference/rcs-agents/test/get-whitelist-status) | #### RCS campaigns (7) | Method | Endpoint | API reference | | ------ | ------------------------------------ | -------------------------------------------------------------------------- | | `POST` | `/campaigns/rcs/list` | [List RCS Campaigns](/api-reference/campaigns/rcs/list) | | `GET` | `/campaigns/rcs/{campaignId}` | [Get RCS Campaign by ID](/api-reference/campaigns/rcs/get) | | `POST` | `/campaigns/rcs` | [Create or Update RCS Campaign](/api-reference/campaigns/rcs/upsert) | | `POST` | `/campaigns/rcs/submit/{campaignId}` | [Submit RCS Campaign](/api-reference/campaigns/rcs/submit) | | `POST` | `/campaigns/rcs/autofill` | [Autofill RCS Campaign Information](/api-reference/campaigns/rcs/autofill) | | `POST` | `/campaigns/rcs/validate` | [Validate RCS Campaign Information](/api-reference/campaigns/rcs/validate) | | `GET` | `/status/rcs-campaign/{campaignId}` | [Get RCS Campaign Status](/api-reference/status/rcs-campaign) | #### Short links and phone-number enrichment (5) | Method | Endpoint | API reference | | ------ | ------------------------ | --------------------------------------------------------------------------- | | `POST` | `/phone-numbers/details` | [Number Intelligence - Get Phone Details](/api-reference/phone-numbers/get) | | `POST` | `/tools/url/list` | [List Shortened URLs](/api-reference/tools/list) | | `GET` | `/tools/url/{linkId}` | [Get Shortened URL](/api-reference/tools/get-url) | | `POST` | `/tools/url` | [Create Shortened URL](/api-reference/tools/create-url) | | `PUT` | `/tools/url/{linkId}` | [Update Shortened URL](/api-reference/tools/update-url) | #### Forms (6) | Method | Endpoint | API reference | | ------- | ------------------------------ | ------------------------------------------------------------------- | | `GET` | `/forms/{id}` | [Get Form](/api-reference/forms/get-form) | | `POST` | `/forms/list` | [List Forms](/api-reference/forms/list-forms) | | `POST` | `/forms/{id}/submissions/list` | [List Form Submissions](/api-reference/forms/list-form-submissions) | | `POST` | `/forms` | [Create Form](/api-reference/forms/create-form) | | `PATCH` | `/forms/{id}` | [Update Form](/api-reference/forms/update-form) | | `POST` | `/forms/send` | [Send Form](/api-reference/forms/send-form) | ## Handling patient information Keep patient information out of support requests, documentation tools, brand and campaign registration, and autofill inputs. Limit access to webhook payloads, message responses, and media links to authorized people and systems. > One API for RCS, iMessage, MMS, and SMS. Build, test, and scale every channel — send your first message in minutes, not weeks.