How NeuroScribe handles protected health information, written plainly, with the parts we have not finished stated as clearly as the parts we have.
Last reviewed September 20, 2026
You are the covered entity. We process data on your behalf, under your direction, and we do not acquire rights to it by handling it. Nothing in the product treats your patients' records as an asset of ours.
Each of these is something you can check, not a posture.
Every connection runs over TLS 1.2 or 1.3. Plain HTTP is refused, not redirected.
Notes, charts and appointments are encrypted at rest with AES-256. Backups carry the same encryption.
Session audio streams straight through to transcription and is never written to our disks or storage. There is no recordings folder, because there is no file storage in the product at all.
Every row carries an owner, and the database refuses a read, edit or delete across that line. This is enforced in the database itself, not in application code, and it is covered by an automated test suite.
When you teach the AI your writing style, the files are read in your browser and never uploaded. Identifiers are stripped before anything is analysed, and the text is discarded once your style has been extracted. Only the style description is kept.
The language model that writes your notes runs under commercial API terms, which exclude your prompts and outputs from model training.
From pressing record to a signed note, in order. The recording is destroyed partway through, which is the part worth knowing.
Audio is captured in your browser and held only for as long as the session runs.
The recording is sent over an encrypted connection and comes back as text with the speakers separated.
Once the transcript exists the recording is gone. There is no file storage in the product, so there is nothing to retain or expose later.
Your template and your own documentation style shape the draft. Nothing here is used to train anyone’s AI.
The note is stored against the chart, encrypted, visible to you alone. Nothing is final until a clinician signs it.
Certifications are documents somebody issues after an audit. We list only the ones we hold.
We operate as a business associate under HIPAA and will execute a Business Associate Agreement with your practice, on every plan. Every subprocessor that can reach PHI is covered by one of its own.
HIPAA makes a business associate directly liable for its subcontractors, so the agreements behind us matter as much as the one in front of you. Here is every company that can touch PHI.
| Subprocessor | What it does | BAA |
|---|---|---|
| Supabase | Database, authentication and hosting of PHI at rest | Executed |
| Vercel | Application hosting and API compute | Executed |
| Anthropic | Note generation and the clinical assistant | Executed |
| AssemblyAI | Speech to text on session audio | Executed |
We do not add a subprocessor that can reach PHI without an executed agreement first. If that list changes we tell account holders by email before the change takes effect, so you always know who is in the chain.
Send them to a person, not a form. We would rather answer a hard question now than have you find the answer later.