Home FAQs HIPAA, BAAs, and data handling

HIPAA, BAAs, and data handling

Last updated on Aug 11, 2026

HIPAA, BAAs, and Data Handling

Scriberapp is designed to support HIPAA-covered entities and their business associates. Below is a summary of our data handling practices.

Business Associate Agreement (BAA)

Scriberapp signs a Business Associate Agreement with every covered entity customer before any clinical data is processed. Your BAA is included in the onboarding documentation and is available for download at any time from Settings > Compliance.

Audio handling

Audio captured during an encounter is streamed over an encrypted connection (TLS 1.3), processed to generate the structured note, and then permanently deleted. Audio is never stored after note generation is complete.

Note storage

Structured note text is retained in encrypted storage (AES-256 at rest) for the duration of your subscription plus a 30-day grace period, unless your organization's data retention policy specifies otherwise.

Access controls

  • Role-based access ensures each provider sees only their own encounters.
  • Administrators can audit access logs at any time from the Admin dashboard.
  • All access is logged and available for compliance review.

Subprocessors

A current list of Scriberapp's subprocessors and their data handling roles is available in our Security documentation at scriberapp.com/security.