Security review before patient-data use

The public pilot is limited to synthetic or role-played scenarios. Before any patient-data workflow, confirm current technical controls, model data flow, access boundaries, retention, BAA requirements, and implementation responsibilities directly with AIDoctorNotes.

This page describes the security approach. It is not a substitute for a formal BAA, vendor review, or your own compliance signoff before live PHI use.

What the architecture actually does

HIPAA posture and what we do not claim

The public pilot is limited to synthetic or role-played scenarios — do not submit PHI. BAA, security, privacy, retention, subprocessor, and implementation requirements must be separately reviewed and confirmed in writing before any patient-data workflow. Drafts require professional review; generation does not approve, file, or authorize clinical use.

HIPAA itself is a regulation, not a certification. We do not claim SOC 2 Type II, HITRUST CSF, ISO 27001, FedRAMP authorization, or published independent penetration test reports. We name the gaps so a prospective customer can make an informed decision.

Subprocessors, incidents, and retention

Before any live implementation, configured providers and required data flows must be disclosed and approved — categories may include cloud infrastructure, speech-to-text transcription, a configured large language model provider, transactional email, and logging or monitoring. No patient-data processing relationship is created by public-pilot access.

Vulnerabilities discovered by external researchers are welcomed at security@aidoctornotes.com — do not include patient information in a report. Audio, draft, note, backup, deletion, export, and legal-hold requirements must be agreed in writing before patient-data use.