Patient privacy isn't a feature — it's the foundation. Here's exactly how we protect the clinical content you trust us with.
Last updated August 15, 2026
Under HIPAA, the provider who records a visit is the Covered Entity. ezScribe operates as a Business Associate processing Protected Health Information ("PHI") on the provider's behalf, and applies the administrative, physical, and technical safeguards listed below to every practice on the platform.
HIPAA compliance is a partnership. ezScribe secures every layer of PHI that flows through our platform. Your practice controls everything that happens on your workforce’s devices, networks, and premises. Here’s the split we operate under, drawn from HIPAA’s Security Rule (45 C.F.R. Part 164, Subpart C) and standard SaaS Business Associate practice.
A quick note. This split is codified in our Terms of Service and Privacy Policy. If a breach originates on the covered-entity side (e.g., a lost unencrypted laptop, a shared password, a workforce member accessing PHI outside of authorized duties), it is generally the practice’s obligation to investigate and report under 45 C.F.R. §§ 164.400–414. ezScribe will cooperate fully and provide relevant audit logs on request.
This page is informational and does not constitute legal advice. Your practice should confirm its HIPAA obligations with qualified healthcare counsel.
We rely on a small number of industry-leading infrastructure partners. Each receives only the minimum data necessary and is under contract to match or exceed our security and HIPAA obligations.
| Partner | Purpose | Handles PHI? |
|---|---|---|
| OpenAI (Whisper, GPT API) | Transcription & clinical summaries | Yes — under BAA & zero-retention policy |
| Cloud hosting provider | App & database hosting | Yes — under BAA |
| Stripe | Subscription billing | No (billing info only) |
| PostHog | Product analytics | No (no PHI sent) |
In the unlikely event of a breach of unsecured PHI, ezScribe will notify the affected Covered Entity without unreasonable delay and no later than 60 days after discovery, consistent with 45 C.F.R. § 164.410. The notice will include the nature of the breach, the PHI involved, the dates, and the steps we are taking to mitigate and prevent recurrence.
If you believe you've found a security vulnerability, please email security@ezscribe.net. We triage responsibly within 1 business day and will credit good-faith researchers in our security-advisory log.