HIPAA-Compliant

Security & HIPAA at ezScribe

Patient privacy isn't a feature — it's the foundation. Here's exactly how we protect the clinical content you trust us with.

Last updated August 15, 2026

Our role: Business Associate

Under HIPAA, the provider who records a visit is the Covered Entity. ezScribe operates as a Business Associate processing Protected Health Information ("PHI") on the provider's behalf, and applies the administrative, physical, and technical safeguards listed below to every practice on the platform.

Our safeguards

Administrative

  • Designated Security Officer & Privacy Officer
  • HIPAA training for all workforce members before PHI access
  • Role-based access control with documented access-review cycles
  • Documented incident-response and breach-notification program
  • Annual HIPAA risk analysis under 45 C.F.R. § 164.308(a)(1)(ii)(A)

Physical

  • Production infrastructure hosted in SOC 2 / HIPAA-audited data centers
  • No PHI on employee laptops; remote-only access via VPN + MFA
  • Physical media disposed of per NIST SP 800-88 guidelines

Technical

  • TLS 1.2+ for all data in transit
  • AES-256 encryption at rest for databases and object storage
  • Tenant isolation at the application and database layer
  • Full audit logging on every PHI access — stored immutably
  • Automatic 30-day deletion of Clinical Content and rolling backup purge
  • MFA required on all administrative and billing accounts

What we do — and don't do — with your Clinical Content

We DO

  • ✓ Encrypt all audio and text in transit (TLS 1.2+)
  • ✓ Encrypt storage at rest (AES-256)
  • ✓ Log every PHI access for audit
  • ✓ Auto-delete Clinical Content after 30 days
  • ✓ Use HIPAA-covered subprocessors under BAA
  • ✓ Notify you immediately of any breach

We do NOT

  • ✗ Sell, rent, or share PHI with anyone
  • ✗ Use PHI to train third-party AI models
  • ✗ Run advertising, profiling, or marketing on PHI
  • ✗ Retain data after you request deletion
  • ✗ Transmit PHI to any non-U.S. subprocessor without your consent
  • ✗ Grant vendor employees routine access to your data

Shared responsibility

HIPAA compliance is a partnership. ezScribe secures every layer of PHI that flows through our platform. Your practice controls everything that happens on your workforce’s devices, networks, and premises. Here’s the split we operate under, drawn from HIPAA’s Security Rule (45 C.F.R. Part 164, Subpart C) and standard SaaS Business Associate practice.

ezScribe is responsible for

  • ✓ PHI encryption at rest (AES-256 / Fernet)
  • ✓ PHI encryption in transit (TLS 1.2+)
  • ✓ Server-side authentication, session management, and access controls
  • ✓ Continuous audit logging of every PHI create / read / update / delete
  • ✓ Automatic 30-day retention purge with a tamper-evident audit trail
  • ✓ Vetting, contracting, and BAAs with our subprocessors
  • ✓ Application-layer security patching, penetration testing, and monitoring
  • ✓ Breach notification to your practice within 60 days per 45 C.F.R. § 164.410

Your practice (Covered Entity) is responsible for

  • • Physical security of laptops, tablets, phones, and workstations used to access ezScribe
  • • Full-disk encryption, screen locks, and mobile-device management (MDM) on workforce devices
  • • Secure networks (WPA2/3 Wi-Fi or VPN); avoiding untrusted public Wi-Fi for PHI work
  • • Unique per-user accounts, strong passwords, and prompt off-boarding of departing staff
  • • Workforce HIPAA training, sanction policies, and role-based access decisions
  • • Physical safeguards in exam rooms and offices (screen orientation, minimum-necessary viewing)
  • • Patient authorizations, Notice of Privacy Practices, and downstream disclosures
  • • Reporting suspected device loss, credential compromise, or workforce incidents to ezScribe promptly

A quick note. This split is codified in our Terms of Service and Privacy Policy. If a breach originates on the covered-entity side (e.g., a lost unencrypted laptop, a shared password, a workforce member accessing PHI outside of authorized duties), it is generally the practice’s obligation to investigate and report under 45 C.F.R. §§ 164.400–414. ezScribe will cooperate fully and provide relevant audit logs on request.

This page is informational and does not constitute legal advice. Your practice should confirm its HIPAA obligations with qualified healthcare counsel.

Our subprocessors

We rely on a small number of industry-leading infrastructure partners. Each receives only the minimum data necessary and is under contract to match or exceed our security and HIPAA obligations.

PartnerPurposeHandles PHI?
OpenAI (Whisper, GPT API)Transcription & clinical summariesYes — under BAA & zero-retention policy
Cloud hosting providerApp & database hostingYes — under BAA
StripeSubscription billingNo (billing info only)
PostHogProduct analyticsNo (no PHI sent)

Breach notification

In the unlikely event of a breach of unsecured PHI, ezScribe will notify the affected Covered Entity without unreasonable delay and no later than 60 days after discovery, consistent with 45 C.F.R. § 164.410. The notice will include the nature of the breach, the PHI involved, the dates, and the steps we are taking to mitigate and prevent recurrence.

Reporting a security issue

If you believe you've found a security vulnerability, please email security@ezscribe.net. We triage responsibly within 1 business day and will credit good-faith researchers in our security-advisory log.