AI SCRIBE · SECURITY & COMPLIANCE

Security Built for PHI, Not Bolted On After the Fact

Every design decision in AI Scribe — from how audio is captured to how long it's retained — starts from the assumption that it's handling protected health information. Here's exactly how that works.

COMPLIANCE & STANDARDS

HIPAA-compliant architectureBAA availableSOC 2-aligned controlsHL7 FHIR R4 / R5AES-256 encryption at restTLS 1.2+ in transit

What "secure" needs to mean for clinical audio

AI Scribe touches some of the most sensitive data an organization holds — live patient conversations. The security model is built around three commitments that hold regardless of deployment size.

1

Minimum necessary retention

Raw audio is kept only as long as needed to generate and validate a note, on a configurable retention window, then permanently deleted — not stored indefinitely by default.

2

No model training on customer data

Patient audio, transcripts, and generated notes are never used to train shared or third-party models. Data is processed solely to deliver the documentation service for that customer.

3

Full auditability

Every access, generation, and write-back event is logged, timestamped, and attributable to a specific user and encounter — built for HIPAA audit and breach-investigation requirements from day one.

How data is protected at each stage

PHI moves through several stages between capture and chart. Each one has its own protection layer.

1

Capture

Audio is encrypted immediately at the point of capture (device or browser) before transmission — it is never sent or stored unencrypted, even briefly.

2

Transit

All data in transit — audio, transcripts, structured notes, API calls — is protected with TLS 1.2 or higher between every service boundary, including EHR write-back.

3

Processing

Transcription and note generation occur in isolated, access-controlled processing environments. PHI is never logged in plaintext application logs or exposed to engineering tooling used for debugging.

4

Storage

Any data persisted (transcripts pending review, generated notes) is encrypted at rest with AES-256, with encryption keys managed separately from the data they protect.

5

Deletion

Raw audio is deleted automatically once it falls outside the configured retention window, following a documented, auditable deletion process rather than manual cleanup.

Access control model

Access to PHI is scoped by role and by need, not granted broadly by default.

Role-based access control

Clinicians, administrators, and support staff each have distinct permission scopes — a support engineer troubleshooting an integration issue does not have the same access as a clinician reviewing a note.

OAuth 2.0 / SMART on FHIR scopes

EHR integration access is limited to the specific FHIR resources required for note write-back — not broad, unscoped access to the patient record.

Multi-factor authentication

Enforced for all administrative and clinical user accounts accessing the platform directly, in addition to any MFA already enforced at the EHR or SSO layer.

Session and device controls

Session timeouts and device-level controls limit how long an authenticated session remains active, reducing exposure from an unattended device.

Deployment models

Different organizations have different constraints around where data can live. AI Scribe supports more than one deployment posture.

ModelWhat It MeansBest Fit For
Managed cloud (multi-tenant)Hosted by Peerbits with logical tenant isolation, encrypted storage, and standard retention policiesMost clinics, telehealth groups, and mid-size practices
Single-tenant cloudDedicated infrastructure and isolated data store for one customer, same security controlsLarger health systems with stricter data-isolation requirements
Private VPC / customer cloudDeployed into the customer's own cloud environment (e.g. their AWS or Azure tenant)Enterprise health systems with existing cloud governance requirements

BUSINESS ASSOCIATE AGREEMENT

A signed BAA is a standard part of onboarding for every healthcare customer, defining how PHI is handled, stored, and protected in line with HIPAA requirements — not a separate negotiation.

WHAT WE ASK IN RETURN

Security is shared. Customers are responsible for their own user access hygiene (strong passwords, MFA where available, prompt offboarding of former staff) — the platform enforces controls, but organizational practices still matter.

Frequently asked questions

Yes. AI Scribe is built on a HIPAA-compliant architecture with encryption in transit and at rest, role-based access controls, full audit logging, and a signed Business Associate Agreement available to every covered entity or business associate customer.

No. Customer audio, transcripts, and generated notes are not used to train shared or third-party models. Data is processed solely to deliver the documentation service for that customer.

Raw audio is retained only as long as needed to generate and validate the structured note, on a configurable retention window set per customer, after which it is permanently deleted.

Yes. A signed BAA is provided as a standard part of onboarding for every healthcare customer.

The platform is built with SOC 2-aligned controls and undergoes regular third-party security assessments. Detailed security documentation, including architecture diagrams and control descriptions, is available upon request for your compliance and legal review.

Yes. Private VPC and customer-managed cloud deployments are supported for organizations with strict data residency or governance requirements. The same security controls apply regardless of deployment model.

Have more questions?

Ask our experts

Need this reviewed by your security or compliance team?

We can share detailed architecture documentation, our standard BAA, and answer questionnaire requests directly — happy to get on a call with your security team.

Request security documentation

Knowledge hub

Expert insights on healthcare security, HIPAA compliance, and clinical data protection.

Award Partner Certification Logo
Award Partner Certification Logo
Award Partner Certification Logo
Award Partner Certification Logo
Award Partner Certification Logo