Security & HIPAA

How Notermed protects patient health information, stated specifically so that your compliance team can verify every claim.

Our approach: claim only what we can prove

Notermed creates, receives, and stores Protected Health Information (PHI) on behalf of the clinics we serve, which makes us a Business Associate under HIPAA. We take that role literally: everything on this page is either visible in our infrastructure, written into our agreements, or demonstrable in the product. We will walk your compliance reviewer through any of it.

You will not find certification badges here that we have not earned. What you will find is a specific, checkable description of how your patients' data is handled.

Safeguards in place today

Grouped by category, so each control can be checked

Technical Safeguards

  • TLS encryption for all data in transit
  • AES-256 encryption at rest for recordings, transcripts, notes, and the database
  • Role-based access control, isolated per clinic
  • Account lockout after repeated failed sign-ins
  • Two-factor authentication for administrator accounts
  • Biometric app lock (Face ID / fingerprint) on mobile

Auditability

  • Every access to patient data writes an audit record
  • Audit trail captures user, action, record, timestamp, and IP
  • Audit records contain no patient data themselves
  • Electronic agreement signatures recorded with content fingerprint
  • Registers available to your clinic on request

Infrastructure

  • Hosted entirely on Amazon Web Services in US regions
  • Business Associate Addendum executed with AWS
  • Note generation via AWS Bedrock, inside our AWS environment
  • Transcription runs at one of three vendors, each under a BAA (listed below)
  • No data ever sent to ChatGPT, OpenAI, or any vendor without a BAA

Never Used for AI Training

Your patients’ recordings, transcripts, and notes are never used to train AI models, ours or anyone else’s.

BAA With Every Clinic

A Business Associate Agreement is signed electronically during onboarding, before any patient data is processed.

Deletion and Return of Data

Clinics can delete sessions and patients, and can request return or destruction of all their data at termination.

Where your data lives, start to finish

United States only

Recordings, transcripts, notes, and the database live in US AWS regions, and note generation runs there too. Transcription is performed in the United States by whichever subprocessor your clinic uses. Patient data is not processed or stored outside the United States at any stage.

Every subprocessor under a BAA

Three companies can process patient data on our behalf, and each one operates under an executed Business Associate Agreement. They are named individually in the list below, along with what each receives.

Breach notification

Our clinic agreement commits us to reporting any impermissible use or disclosure of PHI to your clinic without unreasonable delay, and no later than 15 days after discovery.

Consent-first recording

We provide clinics with a patient consent form template, and our agreement requires documented patient consent before any recorded encounter.

Subprocessors

Every company that can process patient data on our behalf, what it receives, and the agreement it operates under. Current as of September 13, 2026.

CompanyWhat it doesWhat it receivesAgreement
Amazon Web ServicesHosting, storage, database, and note generation (Amazon Bedrock). Also one of the three transcription options (Amazon Transcribe and Transcribe Medical).Recordings, transcripts, notes, patient recordsBusiness Associate Addendum
AssemblyAISpeech-to-text transcription, when a clinic is configured to use it.Visit audio and the resulting transcriptBusiness Associate Agreement
DeepgramSpeech-to-text transcription, when a clinic is configured to use it.Visit audio and the resulting transcriptBusiness Associate Agreement

Which one transcribes your visits

Transcription is a per-clinic setting, so your clinic uses one of the three. We will tell you which on request, and the server records the vendor that received each individual recording. When a recording fails at one vendor and is retried at another, both are recorded, because a breach notice would have to name both.

Adding a subprocessor

No company is added to this list before its Business Associate Agreement is executed. We notify clinics in advance of adding a subprocessor that would process patient data, and this page carries the date it last changed.

Services that receive no patient data

The Clinical Evidence feature searches PubMed, which is run by the US National Library of Medicine. The note itself never leaves our AWS environment: it is reduced there to a generic clinical term of one to three words, such as “asthma exacerbation”, and only that term is sent to PubMed. No patient identifiers, no note text, and no transcript. PubMed is therefore not a Business Associate and is not listed above.

Our payment processor, Stripe, receives your clinic name and billing contact for subscription billing. It receives no patient data of any kind.

Business Associate Agreement

Every clinic signs a Business Associate Agreement with us before any patient data is processed. The signature is part of onboarding, completed electronically, and your clinic keeps a copy of the signed record. Without a signed BAA, no PHI is processed.

Request the BAA text

Questions about compliance?

Ask us anything. If your compliance reviewer wants documentation, we will provide it line by line.

Notermed · CS2 Technologies Inc.
Email: info@notermed.com
Phone: +1 905 749 5338