HIPAA, BAAs, and Data Handling
Scriberapp is designed to support HIPAA-covered entities and their business associates. Below is a summary of our data handling practices.
Business Associate Agreement (BAA)
Scriberapp signs a Business Associate Agreement with every covered entity customer before any clinical data is processed. Your BAA is included in the onboarding documentation and is available for download at any time from Settings > Compliance.
Audio handling
Audio captured during an encounter is streamed over an encrypted connection (TLS 1.3), processed to generate the structured note, and then permanently deleted. Audio is never stored after note generation is complete.
Note storage
Structured note text is retained in encrypted storage (AES-256 at rest) for the duration of your subscription plus a 30-day grace period, unless your organization's data retention policy specifies otherwise.
Access controls
- Role-based access ensures each provider sees only their own encounters.
- Administrators can audit access logs at any time from the Admin dashboard.
- All access is logged and available for compliance review.
Subprocessors
A current list of Scriberapp's subprocessors and their data handling roles is available in our Security documentation at scriberapp.com/security.