BAA & agency review
Everything your privacy officer needs before your clinicians use . Read it, download it, and ask us to sign it.
How your patients' privacy is protected
No patient identifiers
Clinicians are told not to enter names, dates of birth, addresses, record numbers, or insurance IDs. Visits carry a short code only the clinician can match to a patient.
Recording only with consent
Visit recording is off until the clinician turns it on, and the first tap requires confirming the patient agreed. Recordings stay private to that clinician.
Everything deletes on schedule
Saved notes and OASIS assessments are kept for 6 months, then deleted automatically. Recordings and transcripts delete themselves 30 days after they are created. Photos and original shorthand are never kept.
One clinician, one locked record
Access is enforced in the database per signed-in clinician. Administrators see seats and billing — never the content of a note.
Every note is a reviewed draft
A note cannot be saved or sent until the clinician confirms it matches the visit. Editing or rewording clears that confirmation.
Request signed paperwork
Looking for the short version? Read the security & compliance page or the privacy policy.