The public pilot is limited to synthetic or role-played scenarios. Before any patient-data workflow, confirm current technical controls, model data flow, access boundaries, retention, BAA requirements, and implementation responsibilities directly with AIDoctorNotes.
This page describes the security approach. It is not a substitute for a formal BAA, vendor review, or your own compliance signoff before live PHI use.
The public pilot is limited to synthetic or role-played scenarios — do not submit PHI. BAA, security, privacy, retention, subprocessor, and implementation requirements must be separately reviewed and confirmed in writing before any patient-data workflow. Drafts require professional review; generation does not approve, file, or authorize clinical use.
HIPAA itself is a regulation, not a certification. We do not claim SOC 2 Type II, HITRUST CSF, ISO 27001, FedRAMP authorization, or published independent penetration test reports. We name the gaps so a prospective customer can make an informed decision.
Before any live implementation, configured providers and required data flows must be disclosed and approved — categories may include cloud infrastructure, speech-to-text transcription, a configured large language model provider, transactional email, and logging or monitoring. No patient-data processing relationship is created by public-pilot access.
Vulnerabilities discovered by external researchers are welcomed at security@aidoctornotes.com — do not include patient information in a report. Audio, draft, note, backup, deletion, export, and legal-hold requirements must be agreed in writing before patient-data use.