Security · Compliance

Security your compliance team can sign off on

ClinicFrame was built for clinical data from the first line of code. Here is how we protect the visit, the transcript, and the note.

Audio is never stored

The visit audio is processed in real time and discarded. The only things kept are the transcript and the notes you approve.

Encrypted end to end

Data is encrypted in transit (TLS) and at rest. Your transcripts and notes are protected the whole way.

HIPAA compliant, BAA on request

ClinicFrame is HIPAA-compliant, and a signed Business Associate Agreement is available on request for every practice.

Least-privilege access

Role-based access and authentication on every session. Only you reach your patients' data.

Data minimization

We collect the minimum needed to write your notes. We do not sell data or train public models on your PHI.

Audited infrastructure

Runs on hardened cloud infrastructure with continuous monitoring and automated backups.

Logging & monitoring

Access to clinical data is logged and monitored for anomalies, so nothing happens in the dark.

Incident response

A documented incident response plan with breach notification aligned to HIPAA timelines.

Have questions? We're here to help.

Leave us your message and we'll get back to you!

FAQs

Frequently Asked Questions

Is ClinicFrame HIPAA compliant?

Yes. ClinicFrame is HIPAA-compliant, and a signed Business Associate Agreement (BAA) is available on request for every practice.

Do you store the audio from patient visits?

No. Visit audio is processed in real time and discarded. The only things kept are the transcript and the notes you approve.

How is my data encrypted?

Data is encrypted in transit (TLS) and at rest, so your transcripts and notes are protected the whole way.

Who can access patient data in ClinicFrame?

Access is role-based with authentication required on every session, so only you reach your patients' data.

Does ClinicFrame train AI models on my patients' data?

No. We collect the minimum needed to write your notes. We do not sell data or train public models on your PHI.

What happens if there's a security incident?

We maintain a documented incident response plan with breach notification aligned to HIPAA timelines.