SECURITY AND PRIVACY OVERVIEW meant — Clinical Documentation Services Prepared for agency privacy officers, compliance officers, and IT reviewers 1. WHAT THE SERVICE DOES Clinicians use meant to turn their own visit material into a clean, CMS-ready visit-note paragraph and OASIS comment text. Input can be: - dictation or a consented recording of the visit; - rough typed or pasted bullets; - a photograph of the clinician's own handwritten worksheet; - a short visit checklist. The note is always a draft. The clinician must confirm "this note matches the visit" before it can be saved or sent anywhere. 2. PATIENT IDENTIFIERS The service is designed to run without protected health information. No PHI is saved or recorded on meant's servers. Clinicians are instructed, in the product itself, not to enter names, dates of birth, addresses, phone numbers, record numbers, or insurance identifiers. Uploaded paperwork is de-identified on the spot; the note-generation rules strip identifiers if they appear and never reproduce them. Visits are labeled with a short non-identifying code (for example V-KT4821) that only the clinician can match to a patient in the agency EMR. 3. RECORDING AND CONSENT Visit recording is optional and off until the clinician turns it on. The first time a clinician taps Record, the app requires an on-screen confirmation that the patient or their representative was told about the recording and agreed. Recordings are private to the clinician who made them, are used only to produce that visit's note, and delete themselves after 30 days. A clinician can delete any recording immediately. 4. DATA RETENTION - Saved notes and OASIS assessments: deleted automatically 6 months after creation. - Visit recordings and transcripts: deleted automatically after 30 days. - Photographs and original source material: not retained after the note is produced. - Activity history: metadata only (visit type, discipline, timestamp) — no clinical content. - Account data: name, discipline, state, agency name, email. 5. ACCESS CONTROL Every clinical record is owned by one clinician account. Access is enforced in the database with row-level security policies keyed to the signed-in user, so one clinician cannot read another clinician's notes or recordings. Agency or clinic administrators can see seat and billing information only — never the content of a clinician's notes or recordings. 6. ENCRYPTION All traffic uses TLS. Stored data, including audio files, is encrypted at rest. Audio is held in a private storage bucket that is not publicly readable; playback uses short-lived signed links issued only to the owning clinician. 7. AUTHENTICATION Email and password sign-in with per-user accounts. No shared logins. No anonymous access to any clinical data. Sessions are per-device and can be ended by signing out. 8. SUBPROCESSORS - Cloud application, database, and file storage hosting. - AI model providers used to transcribe audio and draft note text. Content sent for drafting is de-identified by design and is not used to train general-purpose models for other customers. A current named list is available on request and is attached to the Business Associate Agreement when one is executed. 9. AUDITABILITY The app records note-creation events and every attempt to send a note to an EMR, with status, for the clinician's own account. Agencies can request an export of this activity for a clinician who authorizes it. 10. INCIDENT RESPONSE Suspected unauthorized access or disclosure is investigated immediately. Affected agencies with a signed Business Associate Agreement are notified without unreasonable delay and no later than 10 calendar days after discovery, with the information available at the time. 11. WHAT THE SERVICE DOES NOT DO - It does not connect to your EMR unless you configure and enable that yourself, and it never sends a note without a clinician tapping Send. - It does not bill, code, or submit claims. - It does not give administrators access to clinical note content. - It does not sell data or use it for advertising. 12. CONTACT support@meant.com — for a Business Associate Agreement, a named subprocessor list, or a security questionnaire.