Last updated: 2025-02-17
Privacy Policy
Introduction
Scribeside is an AI-powered medical scribe and clinical documentation service. We are committed to protecting your privacy and handling health-related information in a manner consistent with applicable law, including HIPAA, and with SOC 2–oriented security practices. This Privacy Policy describes what information we collect, how we use it, and how we protect it.
Information We Collect
We collect and process the following in order to provide and secure the service:
- Account and profile data: Name, email address, and role (e.g., Doctor, Super Admin) for authentication and access control.
- Clinical documentation: Audio recordings of patient encounters, transcripts, and generated SOAP notes that you create or edit within the service. This data is processed to deliver the scribe and documentation features.
- Usage and audit data: Logs of access, actions, and system events for security and compliance. We do not log protected health information (PHI) in our application or audit logs.
How We Use Information
We use the information above to operate the service, authenticate users, enforce access controls, and improve reliability and security. We do not sell your health data or use it for marketing. Clinical documentation is used only as necessary to provide the scribe and documentation features to you and your organization.
HIPAA and Security
We design our systems with HIPAA and SOC 2 considerations in mind:
- No PHI in logs: We do not log protected health information in application or audit logs.
- Encryption: Data is encrypted in transit (TLS) and at rest where applicable.
- Access controls and audit: Access to systems and data is restricted and access events are audited to support security and compliance.
- Business Associate Agreements (BAAs): Where we act as a Business Associate under HIPAA, we enter into BAAs as required.
Data Retention
We retain account and clinical documentation for as long as your account is active and as needed to provide the service and comply with legal obligations. Audit logs are retained for a period that supports security and compliance review. Specific retention periods may be set in agreements with your organization.
Your Rights
You may request access to, correction of, or deletion of your personal data where applicable. To exercise these rights or ask questions about our practices, contact us at hello@scribeside.com.
Contact and Updates
For privacy-related questions or requests, contact us at hello@scribeside.com. We may update this Privacy Policy from time to time. Material changes will be communicated through the service or by other appropriate means. The "Last updated" date at the top of this page indicates when the policy was last revised.