> ## Documentation Index
> Fetch the complete documentation index at: https://docs.revdesk.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a sub-entity

> Rename or flip the `hipaa_enabled` flag. Changing `hipaa_enabled` requires the `compliance:write` scope IN ADDITION to `sub_entities:write`. HIPAA is fail-closed and non-downgradeable: `hipaa_enabled=false` is REJECTED while the umbrella organization is HIPAA-enabled. Enabling HIPAA defaults the sub-entity's call-recording retention to 30 days (adjustable per number afterward).



## OpenAPI

````yaml /openapi.json patch /v1/sub-entities/{id}
openapi: 3.1.0
info:
  title: RevDesk v1 API
  version: 1.0.0
  description: >-
    Connect RevDesk calls, SMS, phone numbers, caller IDs, caller trust, agents,
    contacts, tasks, webhooks, and usage to the rest of your revenue workflow
    with organization-scoped permissions.
  contact:
    name: RevDesk
    email: support@revdesk.com
servers:
  - url: https://api.revdesk.com
security:
  - bearerAuth: []
tags:
  - name: Phone Numbers
  - name: Caller IDs
  - name: Enterprise Registration
  - name: Branded Calling
  - name: Calls
  - name: SMS
  - name: WebRTC
  - name: Reputation
  - name: Usage
  - name: Account
  - name: Agents
  - name: Appointments
  - name: Contacts
  - name: Documents
  - name: Notifications
  - name: Number Health
  - name: Number Registration
  - name: Optimize
  - name: Sandbox
  - name: Sub-entities
  - name: Tasks
  - name: Webhooks
externalDocs:
  description: RevDesk API versioning and deprecation policy
  url: https://docs.revdesk.com/api-reference/versioning-and-deprecation
paths:
  /v1/sub-entities/{id}:
    patch:
      tags:
        - Sub-entities
      summary: Update a sub-entity
      description: >-
        Rename or flip the `hipaa_enabled` flag. Changing `hipaa_enabled`
        requires the `compliance:write` scope IN ADDITION to
        `sub_entities:write`. HIPAA is fail-closed and non-downgradeable:
        `hipaa_enabled=false` is REJECTED while the umbrella organization is
        HIPAA-enabled. Enabling HIPAA defaults the sub-entity's call-recording
        retention to 30 days (adjustable per number afterward).
      operationId: v1_sub_entities_id_patch
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
        - name: Idempotency-Key
          in: header
          required: false
          description: >-
            UUID — when present, deduplicates repeat submissions. See
            /api-reference/idempotency.
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 128
                hipaa_enabled:
                  type: boolean
              additionalProperties: false
      responses:
        '200':
          description: Success
          headers:
            RateLimit:
              $ref: '#/components/headers/RateLimit'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimitPolicy'
            X-RateLimit-Limit:
              $ref: '#/components/headers/XRateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/XRateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/XRateLimitReset'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      name:
                        type: string
                      slug:
                        type:
                          - string
                          - 'null'
                      parent_organization_id:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      hipaa_enabled:
                        type: boolean
                      member_count:
                        type: number
                      phone_number_count:
                        type: number
                      created_at:
                        type: string
                    required:
                      - id
                      - name
                      - slug
                      - parent_organization_id
                      - hipaa_enabled
                      - member_count
                      - phone_number_count
                      - created_at
                    additionalProperties: false
                required:
                  - data
                additionalProperties: false
        '400':
          description: Validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '401':
          description: Unauthorized
          headers:
            WWW-Authenticate:
              $ref: '#/components/headers/WWWAuthenticate'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '403':
          description: Forbidden
          headers:
            WWW-Authenticate:
              $ref: '#/components/headers/WWWAuthenticate'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '409':
          description: Conflict (incl. idempotency conflicts)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '429':
          description: Rate limited
          headers:
            RateLimit:
              $ref: '#/components/headers/RateLimit'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimitPolicy'
            X-RateLimit-Limit:
              $ref: '#/components/headers/XRateLimitLimit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/XRateLimitRemaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/XRateLimitReset'
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
components:
  headers:
    RateLimit:
      description: >-
        Current quota remaining and seconds until reset, using the IETF
        RateLimit structured-field syntax.
      schema:
        type: string
        example: '"default";r=599;t=60'
    RateLimitPolicy:
      description: Named quota policy and one-minute window.
      schema:
        type: string
        example: '"default";q=600;w=60'
    XRateLimitLimit:
      description: Maximum requests allowed in the current one-minute window.
      schema:
        type: integer
    XRateLimitRemaining:
      description: Requests remaining in the current window.
      schema:
        type: integer
    XRateLimitReset:
      description: Unix timestamp in milliseconds when the current window resets.
      schema:
        type: integer
    WWWAuthenticate:
      description: >-
        Bearer challenge with RFC 9728 protected-resource metadata and, on scope
        failures, the required scope.
      schema:
        type: string
    RetryAfter:
      description: Seconds to wait before retrying a rate-limited request.
      schema:
        type: integer
        minimum: 0
  schemas:
    ErrorEnvelope:
      type: object
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
            message:
              type: string
            resolution_hint:
              type: string
            fields:
              type: object
              additionalProperties:
                type: string
            doc_url:
              type: string
              format: uri
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: RevDesk API key
      description: >-
        Organization-scoped RevDesk API key. Each operation declares its
        required permissions in x-required-scopes.
      x-scopes-supported:
        - account:read
        - agents:read
        - agents:write
        - bookings:read
        - brand:read
        - brand:write
        - caller_trust:read
        - caller_trust:write
        - calls:read
        - calls:write
        - contacts:read
        - contacts:write
        - jobs:read
        - jobs:write
        - notifications:write
        - phone_numbers:read
        - phone_numbers:write
        - optimize:read
        - optimize:write
        - sms:read
        - sms:write
        - sub_entities:read
        - sub_entities:write
        - tokens:mint
        - transcripts:read
        - usage:read
        - voice:read
        - voice:webrtc
        - voice:write
        - webhooks:read
        - webhooks:write

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.