Case study

The identity infrastructure behind trusted telehealth

Built the identity infrastructure that let the office number travel with the physician on their personal phone — dissolving the bind between hospital desk phones and exposed personal numbers. The architecture decision was to make trust a product surface, not a compliance footnote.

2013–2017

Early product lead on Doximity Dialer. Owned the identity/verification layer, HIPAA compliance policy, and the EHR integration strategy that put verified calling inside clinical workflows.

Doximity Dialer 'Call from' selector set to OFFICE, with a tooltip explaining the recipient sees this number as caller ID
The identity decision in the product's own words — the clinician picks which number the patient sees, with the office line preselected.

Built the identity infrastructure that let the office number travel with the physician on their personal phone — dissolving the bind between hospital desk phones and exposed personal numbers. The architecture decision was to make trust a product surface, not a compliance footnote.

Physicians need to reach patients but face a structural bind: call from the hospital desk phone (geographically tethered) or call from their personal cell (exposes their personal number permanently — no boundary, no audit trail, safety risk). Most choose neither. The call doesn't happen. And when they do call from a cell phone, patients see 'Unknown Caller' and don't answer. Twilio required verifying access to the outbound phone number before letting us display it as caller ID — the legitimate path, but slower. We found a vendor that let us set any caller ID without verifying ownership. I knew that approach would never pass hospital IT security review. But I also knew hospital IT would likely never approve the product at all — it lets physicians make outbound calls using their office number from a personal cell phone, geographically liberating the number from the hospital phone system. No security team green-lights that on paper. The only path to institutional adoption was to get physicians using it first — build critical mass, and make approval a fait accompli rather than a request.

Physicians need to reach patients but face a structural bind: call from the hospital desk phone (geographically tethered) or call from their personal cell (exposes their personal number permanently — no boundary, no audit trail, safety risk). Most choose neither. The call doesn't happen. And when they do call from a cell phone, patients see 'Unknown Caller' and don't answer. Twilio required verifying access to the outbound phone number before letting us display it as caller ID — the legitimate path, but slower. We found a vendor that let us set any caller ID without verifying ownership. I knew that approach would never pass hospital IT security review. But I also knew hospital IT would likely never approve the product at all — it lets physicians make outbound calls using their office number from a personal cell phone, geographically liberating the number from the hospital phone system. No security team green-lights that on paper. The only path to institutional adoption was to get physicians using it first — build critical mass, and make approval a fait accompli rather than a request.

Took the shortcut — used a vendor that didn't require caller ID verification — because the legitimate path would never get approved. Hospital IT wouldn't pre-approve a product that lets physicians use their office number from a personal cell phone. The only way through was around: ship to physicians directly, build critical mass, and let institutional approval follow adoption instead of preceding it. Built the HIPAA compliance policy and Epic Haiku integration to give hospital IT a documented basis to clear the product once it was already in use.

Designed and shipped HIPAA-compliant verified caller-ID and fallback workflows ensuring the clinician's office was the visible, trusted identity on all outbound calls. Authored the HIPAA compliance policy — policies, procedures, and the white paper that gave hospital security reviews a documented basis to clear the product. Partnered with legal and hospital IT to clear EHR integration across multiple systems. Led the Epic Haiku integration putting one-tap verified calling inside the chart the clinician was already in.

Established the identity layer Dialer scaled on. Nine years after I left Doximity, the product is still the #1 ranked telehealth platform by health system CIOs — five years running, beating Microsoft Teams and Zoom. Doximity now conducts 300,000+ voice and video visits per average weekday across 200+ health systems, reaching ~45% of U.S. physicians with paid enterprise licenses. Five direct competitors tried to build a physician-focused Dialer and failed. Pickup rates 3x higher than competitors — patients see the office number, not 'spam risk.' The architecture held.

1 Doximity Dialer launched in 2016 as a physician calling product.

Launch evidence for the caller-ID product context.

Doximity / PR Newswire

2 Dialer conducts 300,000+ voice and video visits per average weekday across 200+ health systems.

8-K filed Nov 6, 2025. CEO prepared remarks: 300K+ daily visits, 200+ health system clients, ~45% of U.S. physicians with paid licenses.

Doximity Q2 FY2026 Earnings Call (Nov 6, 2025)

3 Dialer ranked #1 best-in-class telehealth platform by health system CIOs, five years running, beating Microsoft Teams and Zoom.

8-K filed Feb 5, 2026. Pickup rates 3x higher than competitors due to telco relationships and caller ID attestation.

Doximity Q3 FY2026 Earnings Call (Feb 5, 2026)

4 Over 300,000 unique active providers used Doximity telehealth tools in the quarter ended March 31, 2021.

Dated SEC filing, cited in place of undated company marketing copy.

Doximity Form S-1

5 Dialer integrated with Epic Haiku.

Public integration evidence for clinical-workflow reach.

Doximity press

6 Dialer appears in Epic Showroom.

Public listing evidence for the product ecosystem.

Epic Showroom
1 Doctor opens Dialer 2 Enters patient phone number 3 System sets office number as caller ID 4 Patient sees 'Dr. Smith's Office' on phone 5 Patient answers 6 Call connected with office identity
  • Physicians can't share personal phone numbers with patients — boundary, safety, liability, and no audit trail. The office number had to serve as the trust proxy.
  • Hospital desk phones tether physicians to a physical location. The product had to liberate the office number without exposing the personal number.
  • Hospital IT security reviews would never pre-approve a product that lets physicians use office numbers from personal devices — adoption had to precede approval.
  • Office number as caller ID via vendor integration, with fallback paths for carrier rejection.
  • HIPAA compliance policy, procedures, and white paper authored as product infrastructure.
  • Audit-ready call logs and identity verification records.
  • Epic Haiku integration putting calling inside the clinical workflow.
  • Built the identity infrastructure powering 300,000+ daily voice and video visits across 200+ health systems (per Doximity Q2 FY2026 earnings call, Nov 2025).
  • Put verified identity directly into the clinician's primary workflow via Epic Haiku.
  • Authored the HIPAA compliance posture that gave hospital security teams a documented basis to clear the product.
  • Drove iOS ratings from 3.7 to 4.8 stars through reliability and trust engineering.
  • HIPAA compliance policy and white paper adopted as the product's security review basis.
  • Caller ID mapping and carrier-interaction documentation.
  • Epic Haiku integration architecture for in-workflow verified calling.

← Back to portfolio