Security & Compliance

Clinical conversations deserve clinical-grade protection. Here is exactly how DocuMD handles the data your patients trust you with.

HIPAA-ready infrastructure

DocuMD is designed to support HIPAA-compliant workflows. Protected health information is handled on infrastructure configured for healthcare workloads, with the safeguards described on this page applied to audio recordings, transcripts and generated notes.

Business Associate Agreement (BAA)

A Business Associate Agreement is available for practices on paid plans. Contact us at support@documd.com to request and execute a BAA before processing patient data.

Encryption in transit and at rest

All data — audio, transcripts and clinical notes — is encrypted in transit using TLS and encrypted at rest. Recordings are encrypted from the moment they are captured.

Access controls

Access to clinical data is restricted to the authenticated account that created it. Internal access by DocuMD personnel is limited, role-based and granted only when required to operate or support the service.

Audit logging

Account activity and access to recordings and notes are logged, providing an audit trail for security review and compliance needs.

Data-retention controls

Recordings and notes are retained under your control. You choose what to keep and can remove individual recordings and notes from your account at any time.

Patient-consent support

Recording a patient encounter requires patient consent under applicable state and federal law. DocuMD supports consent-based workflows, and clinicians remain responsible for obtaining and documenting consent before recording.

Data deletion

You can delete individual recordings and notes in the app, and you can request full deletion of your account and all associated data at any time via our account deletion process or by contacting support@documd.com.

AI model training

Customer clinical data is used to provide the service — transcription and note generation for your account. It is not used to train models for other customers without explicit consent.

Data hosting

Customer data is hosted in secure cloud data centers located in the United States.

Subprocessors

DocuMD uses a limited set of vetted infrastructure and AI service providers to deliver the product. A current list of subprocessors is available on request at support@documd.com.

A note on compliance claims

HIPAA compliance is a shared responsibility between DocuMD and your practice. DocuMD provides infrastructure and safeguards designed to support HIPAA-compliant workflows; your practice remains responsible for its own policies, workforce training and patient consent. All AI-generated documentation must be reviewed and approved by the clinician before use.

Have a security questionnaire or need details for your compliance team?

Contact us