Case study

The patient sees the office, not the cell phone

Built the identity layer that let a physician call a patient from their own phone while the patient saw the office number — so the call got answered and the physician's cell number stayed private. Trust had to be a product surface, not a compliance footnote.

Doximity Dialer 'Call from' selector set to OFFICE, with a tooltip explaining the recipient sees this number as caller ID
The identity decision in the product's own words — the clinician picks which number the patient sees, with the office line preselected.

9 years after I left, still carrying the call shielding the identity layer was built for.

  • 300,000+

    Calls on an average workday

    Doximity's own figure, February 2026.

  • 250+

    Hospitals and health systems

    Still carrying the call shielding built here.

  • 9 years

    Since I left

    The 2016 identity layer, unchanged.

Physicians need to reach patients but face a structural bind: call from the hospital desk phone, which means being at the hospital, or from a personal cell, which gives the number away for good — no boundary, no audit trail, and a safety risk. Most choose neither, and the call doesn't happen. When they do call from a cell phone, patients see 'Unknown Caller' and don't answer.

A product like that would never survive a hospital IT security review up front — no security team green-lights physicians placing outbound calls under an office number from a personal phone. 2

Proved it myself over a weekend: a working prototype placing outbound calls under an unverified caller ID, launched on that vendor deliberately. The boundary: the caller ID was the physician's own office number, on their own device, at their own choice — an identity they already legitimately held, with no clinical decision-making in the loop.

Hospital authorization came in stages, after physicians were already using it; the caller-ID route itself did not change while I was there. 2

Twilio-verified caller ID Not chosen

The legitimate path — Twilio required proving control of a number before displaying it as caller ID. Compliant, but slower to ship.

Unverified vendor caller ID Chosen

A vendor offered to set any caller ID without proof of control. Faster to ship, and the account-level identity verification was the protection layer underneath it.

The risk stayed with the person choosing, and every caller was an identity-verified Doximity member, so the platform knew who was behind the number.

The bind: desk phone, personal cell, or the office number on your own phone
Hospital desk phonePersonal cellDialer
Where you must be At the hospital Anywhere Anywhere, on your own device
What the patient sees The hospital's number “Unknown Caller” — and the personal number, given away for good The office number: “Dr. Smith's Office”
Audit trail None Audit-ready call logs and identity verification records
Whether the call is answered Not answered; most physicians choose not to call at all Answered

Designed and shipped HIPAA-compliant verified caller ID and fallback workflows, making the clinician's office the visible, trusted identity on every outbound call.

Partnered with legal and hospital IT to clear EHR integration across multiple systems, including the Epic Haiku integration for one-tap verified calling inside the chart. 56

  1. Adopt — physicians using it on the vendor route, the risk staying with the person choosing
  2. Document — the HIPAA compliance policy, inherited from the 2014 messaging work
  3. Clear — hospital IT and the Epic Haiku integration, for a product already in use

Established the identity layer Dialer scaled on. The launch cohort converted: of 904 physicians emailed, 36 placed a call within days, and daily volume went from roughly ten to nearly seven hundred in the first ten days. While I was there, the iOS rating rose from 3.7 to 4.8 stars across the whole app portfolio. 34

Caller-ID identities in the 2016 spec
IdentityWhat it isLifetime
Office The clinician's office number — the preselected default A number the clinician already holds
Back office A back-office line, selectable per call A number the clinician already holds
Mobile The clinician's own mobile number, chosen deliberately A number the clinician already holds
Ghost An ephemeral number for the case where no owned number fits 24 hours
Four ways to prove you were a clinician
MethodWhat it provesRetained?
Medical email domain Clinician status, by an address at a medical institution
DEA number Clinician status, by the prescriber registration No — used to verify, never stored
License photo Clinician status, by a photograph of the license
Fax Clinician status, by a faxed document
Account-level identity verification was the protection layer under the unverified caller ID: every caller was a verified Doximity member.
inbound_connect outbound_connect terminate finish timeout outbound_finish inbound_finish finish initialized inbound_connected clinician's leg is up fully_connected both legs bridged terminating finished timed_out one leg ended, the other still up inbound_alone patient hung up outbound_alone clinician hung up
The bridge-line call state machine, redrawn from the Dialer engineering diagram. The system calls the clinician first and the patient second, then joins the two legs — which is why the office number can be the caller ID without the personal number ever reaching the patient. Each leg can end independently, so the graph carries a distinct state for whichever side hung up first.
0 200 400 600 Oct 22 Oct 24 Oct 26 Oct 28 Oct 30 Nov 1 2016 launch email — 904 sent
Daily calls in the first eleven days, read off the launch review chart. It opens at roughly five calls a day and reaches about six hundred and eighty. The step on 27 October is the launch email: 904 physicians mailed, 125 clicked, 59 signed in, 36 placed a call.

The sequence is where a principle I now design by was earned rather than contradicted — adoption may precede institutional approval only while the risk stays with the person choosing. When the risk is clinical, approval comes first.

When the call connects, a lab result gets communicated tonight instead of next week. A post-discharge follow-up reaches the patient before a complication sends them back to the ER. A physician who gets a biopsy result at 7pm can call from home — the patient sees the office number and answers, the personal boundary stays intact, and the diagnosis doesn't wait until morning.

The first sign it was working wasn't a metric: medical residents I'd gone to undergrad with told me they were getting more sleep at night — they could call patients from home with the office number instead of staying at the hospital to use the desk phone.

1 Dialer launch

Doximity Dialer launched in 2016 as a physician calling product.

Launch evidence for the caller-ID product context.

Doximity / PR Newswire

2 Launch rationale, in my words

I stated the product's rationale on Doximity's blog at launch: “Easier communication leads to more communication, and greater communication leads to better health outcomes.”

Dead at the original URL; cited to the Internet Archive snapshot. The title names the behavior the product replaced — physicians blocking caller ID with *67 and going unanswered.

Doximity Blog, “Goodbye *67, Hello Doximity Dialer” (Internet Archive)

3 Dialer call volume

Dialer carried more than 300,000 calls on an average workday last quarter, across 250+ hospitals and health systems.

Doximity's own reported figure for the quarter, published in its investor newsroom rather than in an SEC filing.

Doximity Investor Relations (5 February 2026)

4 Telehealth provider volume

Over 300,000 unique active providers used Doximity telehealth tools in the quarter ended March 31, 2021.

Dated SEC filing, cited in place of undated company marketing copy. The filing's words: “We had over 300,000 unique active providers use our telehealth tools in the quarter ended March 31, 2021.” It defines a provider broadly — physicians, doctors of osteopathy, physician assistants, nurse practitioners, and medical students.

Doximity Form S-1 (filed 28 May 2021)

5 Epic Haiku integration

Dialer integrated with Epic Haiku.

Public integration evidence for clinical-workflow reach.

Doximity press

6 Epic Showroom listing

Dialer appears in Epic Showroom.

Public listing evidence for the Epic integration.

Epic Showroom

Documents described, not republished

  • Caller ID mapping The August 2016 MVP spec, when the product was still called CallPatient — tabulated above.
  • The decision to defer phone verification In the same spec, four SMS-verification screens are struck through in red: identity was already established by the Doximity account behind the app, so verifying the handset again was cost without protection.
  • Identity verification methods The annotated iOS spec, tabulated above.
  • HIPAA policies, procedures, and white paper Written in 2014 for the messaging products.

Launch figures and the weekend prototype come from my launch review.

Continued Transcarent Four specialty programs on one routing architecture