HIPAA-Aware Architecture

Home > Security

HIPAA-Aware Architecture

Clinic Scribe is built to support the requirements of HIPAA (Health Insurance Portability and Accountability Act). Built on Microsoft Azure, with support for HIPAA-compliant architecture and audit logging. While we are currently in pilot phase and not a covered entity, our infrastructure and policies are designed with full compliance in mind.

  • End-to-end encryption (SSL/TLS for transit, AES-256 for storage)
  • Role-based access controls
  • Secure server environments
  • HIPAA-aware design; MFA; audit logs; configurable retention; 
  • U.S. data residency.
01

Encryption Standards

All audio, transcripts, and generated notes are encrypted

In Transit – Data is encrypted using TLS 1.2+

  • At Rest – Transcripts and notes stored securely with AES-256 encryption We do not retain any voice recordings long-term. Audio is securely deleted after real-time processing, unless explicitly saved for troubleshooting during the pilot (opt-in only).

02

Partner in Patient Privacy Protection

We partner with HIPAA-friendly infrastructure providers and audit our security practices regularly.

Clinic Scribe is hosted on secure, U.S.-based cloud servers with reliable uptime, daily backups, and automated threat detection.

Security Assurance

Our AI tool ensures HIPAA compliance and data security for all your clinic’s sensitive information.

Minimal Data Retention
  • Audio is processed and then deleted
  • Only necessary metadata is kept temporarily for product improvement (with your consent)
  • You control when notes are exported, stored, or deleted
User Control & Consent
  • You choose when to record and when to stop
  • You decide what notes are saved or deleted
  • We never access or use your clinic data for training AI models without permission
With/With Out EHR Integration

Clinic Scribe operates independently of your EHR system. We do not require access to your patient records or back-end integration. You retain full control over where and how you use the output.