Case study 2 of 5 · Decided by approval

The patient sees the office, not the cell phone

As founding product lead, I originated the identity layer that let a physician call a patient from their own phone while the patient saw the office number — so the call got answered and the physician’s cell number stayed private. Doximity had already verified every physician, which is what made it safe to show the office number.

Doximity Dialer “Call from” selector set to OFFICE, with a tooltip explaining the recipient sees this number as caller ID
The identity decision in the product’s own words — the clinician picks which number the patient sees, with the office line preselected.
  • 300,000+

    Calls on an average workday

    Doximity’s own figure, February 2026.

  • 250+

    Hospitals and health systems

    From the same Doximity release.

  • 9 years

    Still running since I left in 2017

    Originated as founding product lead; the caller-ID route was unchanged when I left.

Physicians need to reach patients but face a bind: call from the hospital desk phone, which means being at the hospital, or from a personal cell, which gives the number away for good — no boundary, no audit trail, and a safety risk. Most choose neither, and the call doesn’t happen. When they do call from a cell phone, patients see “Unknown Caller” and don’t answer.

I did not believe we could get that through a hospital IT security review as a proposal. A physician placing outbound calls under an office number from a personal phone was something those reviews had no category for, and I expected to lose the argument on paper. Authorization did come — after the product was in use, and in stages. 2 Doximity Blog, “Goodbye *67, Hello Doximity Dialer” (Internet Archive)

I proved it myself over a weekend with a working prototype placing outbound calls through a vendor that would show any caller ID without checking it, and launched on that vendor deliberately. The boundary: the caller ID was the physician’s own office number, on their own device, at their own choice — an identity they already legitimately held, with no clinical decision-making in the loop.

Hospital authorization came in stages, after physicians were already using it; the caller-ID route itself did not change while I was there. 2 Doximity Blog, “Goodbye *67, Hello Doximity Dialer” (Internet Archive)

Twilio-verified caller ID Not chosen

Named in the April proposal as our chief 3rd party vendor with pricing. Every number had to be proven before it could be displayed; launch would have waited on verification.

Vendor without proof of control Chosen

Named in the August spec. The physician chose an office number they legitimately controlled; the risk stayed with the physician, and the account carried the protection.

The risk stayed with the person choosing, and every caller was an identity-verified Doximity member, so the platform knew who was behind the number. Hospital authorization followed adoption in stages.

The bind: desk phone, personal cell, or the office number on your own phone
Compared onHospital desk phonePersonal cellDialer
Where you must be At the hospital Anywhere Anywhere, on your own device
What the patient sees The hospital’s number “Unknown Caller” — and the personal number, given away for good The office number: “Dr. Smith’s Office”
Audit trail — None Audit-ready call logs and identity verification records
Whether the call is answered — Not answered; most physicians choose not to call at all Answered

I designed and shipped the HIPAA-compliant caller-ID and fallback workflows, so the clinician’s office was the number the patient saw on every call.

I worked with legal and hospital IT to clear EHR integration across several systems, including the Epic Haiku integration for one-tap calling inside the chart. 5 Doximity press 6 Epic Showroom

  1. Adopt — physicians using it on the vendor route, the risk staying with the person choosing
  2. Document — the HIPAA compliance policy, carried over from the one I wrote in 2014 for Doximity’s messaging products
  3. Clear — hospital IT and the Epic Haiku integration, for a product already in use

The identity layer shipped, and Dialer scaled on it. The launch cohort converted: of 904 physicians emailed, 36 placed a call within days, and daily calls went from roughly five to about 680 in the first eleven days. 3 Doximity Investor Relations (5 February 2026) 4 Doximity Form S-1 (filed 28 May 2021)

Caller-ID identities in the 2016 spec
IdentityWhat it isWhere the number comes from
Office The clinician’s office number — the preselected default One the clinician already holds
Back office A back-office line, selectable per call One the clinician already holds
Mobile The clinician’s own mobile number, chosen deliberately One the clinician already holds
Ghost A temporary number the product issues when the clinician has no owned number that fits Issued by the product; expires after 24 hours
Four ways to prove you were a clinician
MethodWhat it provesWhat the spec says about retention
Medical email domain Clinician status, by an address at a medical institution Not stated either way
DEA number Clinician status, by the prescriber registration No — used to verify, never stored
License photo Clinician status, by a photograph of the license Not stated either way
Fax Clinician status, by a faxed document Not stated either way
Account-level identity verification was the protection layer under the unverified caller ID: every caller was a verified Doximity member.
inbound_connect outbound_connect terminate finish timeout outbound_finish inbound_finish finish initialized inbound_connected clinician’s leg is up fully_connected both legs bridged terminating finished timed_out one leg ended, the other still up inbound_alone patient hung up outbound_alone clinician hung up
The bridge-line call state machine, redrawn from the Dialer engineering diagram. The system calls the clinician first and the patient second, then joins the two legs — which is why the office number can be the caller ID without the personal number ever reaching the patient. Each leg can end independently, so the graph carries a distinct state for whichever side hung up first.
0 200 400 600 Oct 22 Oct 24 Oct 26 Oct 28 Oct 30 Nov 1 2016 launch email — 904 sent
Daily calls in the first eleven days, read off the launch review chart. It opens at roughly five calls a day and reaches about six hundred and eighty. The step on 27 October is the launch email: 904 physicians mailed, 125 clicked, 59 signed in, 36 placed a call.

Adoption may come before official approval only while the risk stays with the person choosing. When the risk is clinical, approval comes first.

It is also the case that could most easily have broken that rule. The caller ID was unverified; what kept the risk with the physician was that every caller was a verified Doximity member, calling as an identity they already held.

The first sign it was working wasn’t a metric: medical residents I’d gone to undergrad with told me they were getting more sleep at night — they could call patients from home with the office number instead of staying at the hospital to use the desk phone.

1 Dialer launch

Doximity Dialer launched in 2016 as a physician calling product.

Doximity’s launch announcement.

2 Launch rationale, in my words

I stated the product’s rationale on Doximity’s blog at launch: “Easier communication leads to more communication, and greater communication leads to better health outcomes.”

The original post is offline; this is the Internet Archive copy. The title names what Dialer replaced: physicians blocking caller ID with *67, and patients not answering.

3 Dialer call volume

Doximity reported in February 2026 that Dialer carries more than 300,000 calls on an average workday, across 250+ hospitals and health systems.

Doximity’s own figure, from its investor newsroom.

4 Telehealth provider volume

Over 300,000 unique active providers used Doximity telehealth tools in the quarter ended March 31, 2021.

From Doximity’s SEC filing: “We had over 300,000 unique active providers use our telehealth tools in the quarter ended March 31, 2021.” Its count of providers includes physicians, doctors of osteopathy, physician assistants, nurse practitioners, and medical students.

5 Epic Haiku integration

Dialer integrated with Epic Haiku.

Doximity’s announcement of the integration.

6 Epic Showroom listing

Dialer appears in Epic Showroom.

Dialer’s listing in Epic’s app marketplace.

Documents described, not republished

  • Caller ID mapping The August 2016 MVP spec, when the product was still called CallPatient — tabulated above.
  • The decision to defer phone verification In the August 2016 MVP spec, four SMS-verification screens are struck through in red with the contemporaneous note: “Let’s defer verifying the user’s phone until version 1.1… We do already have them in as a registered & verified doximity user so that’s a pretty good protection layer.” The account already carried the verification; reverifying was friction without protection.
  • Identity verification methods The annotated iOS spec, tabulated above.
  • HIPAA policies, procedures, and white paper Written in 2014 for the messaging products.

Launch figures and the weekend prototype come from my launch review. The 2026 call volume is Doximity’s own reported figure and is evidence about the product, not about which of its parts are still mine: I can say the caller-ID route was unchanged when I left in 2017, and nothing public says what the identity layer looks like now.

Continued Transcarent Four specialty programs on one routing architecture

Revised