BAA & agency review

Everything your privacy officer needs before your clinicians use . Read it, download it, and ask us to sign it.

How your patients' privacy is protected

No patient identifiers

Clinicians are told not to enter names, dates of birth, addresses, record numbers, or insurance IDs. Visits carry a short code only the clinician can match to a patient.

Recording only with consent

Visit recording is off until the clinician turns it on, and the first tap requires confirming the patient agreed. Recordings stay private to that clinician.

Everything deletes on schedule

Saved notes and OASIS assessments are kept for 6 months, then deleted automatically. Recordings and transcripts delete themselves 30 days after they are created. Photos and original shorthand are never kept.

One clinician, one locked record

Access is enforced in the database per signed-in clinician. Administrators see seats and billing — never the content of a note.

Every note is a reviewed draft

A note cannot be saved or sent until the clinician confirms it matches the visit. Editing or rewording clears that confirmation.

Request signed paperwork

Looking for the short version? Read the security & compliance page or the privacy policy.