Security.
Built with healthcare data protection and privacy requirements in mind. Here is exactly what that means today — including where we are not yet certified.
AI transparency
AI generates a draft
The pipeline is extract-only — it structures what was said. It does not invent findings, diagnoses, or plans.
Clinicians review and edit
Every field is editable before anything is saved or printed.
Clinicians decide the record
The system reflects what was said. It does not decide what should happen next — that stays with the clinician.
Access controls
Per-user sign-in
Each staff member signs in with their own PIN, so every recorded session is tied to the person who created it.
Role-aware recording
Recordings are tagged to the signed-in user’s role — nurse, duty medical officer, or consultant.
Encrypted infrastructure
Data is stored on managed infrastructure with encryption at rest and TLS in transit.
Data residency
India is our data residency posture. We are in the process of migrating hosting to an India region — we'll state exactly where things stand as part of any Data Processing Agreement, rather than a blanket present-tense claim.
Before go-live
We sign a Data Processing Agreement before go-live, naming every subprocessor involved in handling patient data — including OpenAI, which powers transcription and structuring. We are working through a structured compliance program aligned with India's Digital Personal Data Protection (DPDP) Act.
What we don't claim
We would rather tell you plainly than let you assume. AI Clinical Scribe does not currently hold:
- — HIPAA compliance
- — SOC 2 certification
- — HITRUST certification
- — FDA clearance or approval
- — A comprehensive, independently audited access log
- — NHA or ABDM certification, or ABDM Gateway/HIP/Fidelius/ABHA integration
- — Production-scale SNOMED CT clinical coding — our SNOMED International Affiliate application is still in progress
- — A live, deployed integration with any external EMR/EHR system
If any of these are a requirement for your hospital, ask us directly — we'll tell you exactly where we stand.
Have a specific security question?
Ask us directly — we'll answer plainly, including anything we haven't built yet.