PHI is encrypted in transit (TLS) and at rest. There is no mode of the product where patient data travels or sits unencrypted.
Providers, the scribe team, billers, and administrators each see the work that's theirs — access follows the role, not the login.
Every draft, edit, handoff, signature, and claim action is logged and traceable — who did what, when, on which encounter.
AI drafts and organizes — it never signs. Every note requires provider review and signature, and AI output is always labeled as a draft.
The practice owns its notes, claims history, and operational data. Export at any time — no lock-in by hostage-taking.
We operate as a HIPAA business associate and sign a BAA with every practice. A SOC 2 audit is in progress; we'll share status and reports on request.
Security review is part of every serious purchase in healthcare. We'll provide our security overview, BAA template, and SOC 2 status directly — and answer your security questionnaire.