Privacy Policy

Version 1.1 · Last updated: September 13, 2026

1. Introduction

Notermed ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our medical transcription and documentation platform.

2. Information We Collect

2.1 Personal Information

We may collect personal information that you voluntarily provide when using our services, including:

  • Name and contact information (email, phone number)
  • Professional credentials and practice information
  • Account login credentials
  • Billing and payment information

2.2 Protected Health Information (PHI)

In the course of providing our services, we process Protected Health Information on behalf of healthcare providers. This includes:

  • Audio recordings of patient-provider conversations
  • Transcriptions of medical consultations
  • Generated clinical notes and documentation
  • Patient demographic information

2.3 Usage Information

We automatically collect certain information when you use our platform:

  • Device information and browser type
  • IP address and location data
  • Usage patterns and feature interactions
  • Performance and error data

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide and maintain our transcription and documentation services
  • To process and complete transactions
  • To improve our service, using aggregate usage patterns only. Patient health information (recordings, transcripts, and notes) is never used to train AI models, ours or anyone else's.
  • To communicate with you about your account and our services
  • To comply with legal obligations and enforce our agreements

4. Data Security

We protect your information with the following measures:

  • TLS encryption for all data transmission
  • AES-256 encryption for data at rest
  • Role-based access controls, isolated per clinic
  • Audit logging of every access to patient data
  • All patient data hosted in United States AWS regions under a Business Associate Addendum, and processed only in the United States by every subprocessor named in Section 7

5. Data Retention

We retain your information for as long as necessary to provide our services and comply with legal obligations. Specifically:

  • Account information: Retained while your account is active
  • Audio recordings: Retained under your clinic's retention policy and deleted at your clinic's direction
  • Clinical notes: Retained according to your organization's policies
  • Access audit records: Retained for the life of the account to support HIPAA audit requirements (these record who accessed what and when, never the patient data itself)

6. Your Rights

Depending on your location, you may have certain rights regarding your personal information:

  • Right to access your personal information
  • Right to correct inaccurate information
  • Right to delete your information (medical records are deleted at your healthcare provider's direction, consistent with their legal retention obligations)
  • Right to data portability
  • Right to opt out of marketing communications

7. Subprocessors and Third-Party Services

Protected Health Information is disclosed to three service providers, each operating under an executed HIPAA Business Associate Agreement, and each processing that information only in the United States:

  • Amazon Web Services hosts the platform and generates clinical notes (Amazon Bedrock). It also provides one of our three transcription options
  • AssemblyAI provides speech-to-text transcription for clinics configured to use it
  • Deepgram provides speech-to-text transcription for clinics configured to use it

Transcription is a per-clinic setting, so a given clinic's audio is processed by one of these three. We record which provider received each individual recording, including both providers where a recording failed at one and was retried at another, and we will tell your clinic which provider it uses on request. The current list, with the date it last changed, is published on our Security & HIPAA page. We notify clinics in advance of adding any subprocessor that would process patient data, and no provider is added before its Business Associate Agreement is executed.

Two services appear in our systems but receive no patient health information. The Clinical Evidence feature searches PubMed, operated by the US National Library of Medicine: the clinical note is reduced within our AWS environment to a generic medical term of one to three words, and only that term is transmitted. No note text, transcript, or patient identifier is sent. Our payment processor receives your clinic name and billing contact only. Neither is a Business Associate.

No patient health information is sent to ChatGPT, OpenAI, or any other provider that has not executed a Business Associate Agreement with us.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.

9. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Notermed Privacy Team · CS2 Technologies Inc.
Email: info@notermed.com
Phone: +1 905 749 5338
Address: 2424 Finch Ave W, Unit 14, Toronto, ON M9M 2E2, Canada