Security & HIPAA

How Notermed protects patient health information — stated specifically, so your compliance team can verify every claim.

Our approach: claim only what we can prove

Notermed creates, receives, and stores Protected Health Information (PHI) on behalf of the clinics we serve, which makes us a Business Associate under HIPAA. We take that role literally: everything on this page is either visible in our infrastructure, written into our agreements, or demonstrable in the product — and we will walk your compliance reviewer through any of it.

You will not find certification badges here that we have not earned. What you will find is a specific, checkable description of how your patients' data is handled.

Safeguards in place today

Comprehensive protection at every level

Technical Safeguards

  • TLS encryption for all data in transit
  • AES-256 encryption at rest — recordings, transcripts, notes, and database
  • Role-based access control, isolated per clinic
  • Account lockout after repeated failed sign-ins
  • Two-factor authentication for administrator accounts
  • Biometric app lock (Face ID / fingerprint) on mobile

Auditability

  • Every access to patient data writes an audit record
  • Audit trail captures user, action, record, timestamp, and IP
  • Audit records contain no patient data themselves
  • Electronic agreement signatures recorded with content fingerprint
  • Registers available to your clinic on request

Infrastructure

  • Hosted entirely on Amazon Web Services in US regions
  • Business Associate Addendum executed with AWS
  • AI transcription via AWS Transcribe Medical
  • Note generation via AWS Bedrock — inside our AWS environment
  • No data ever sent to ChatGPT, OpenAI, or any vendor without a BAA

Never Used for AI Training

Your patients’ recordings, transcripts, and notes are never used to train AI models — ours or anyone else’s.

BAA With Every Clinic

A Business Associate Agreement is signed electronically during onboarding, before any patient data is processed.

Your Data, Your Control

Clinics can delete sessions and patients, and can request return or destruction of all their data at termination.

Where your data lives, start to finish

United States only

All PHI is processed and stored in US AWS regions. Patient data does not leave the United States at any point in the pipeline — recording, transcription, note generation, or storage.

One subprocessor, under BAA

Amazon Web Services is our only subprocessor with access to PHI, operating under an executed Business Associate Addendum. There are no other vendors in the patient-data path.

Breach notification

Our clinic agreement commits us to reporting any impermissible use or disclosure of PHI to your clinic without unreasonable delay, and no later than 15 days after discovery.

Consent-first recording

We provide clinics with a patient consent form template, and our agreement requires documented patient consent before any recorded encounter.

Business Associate Agreement

Every clinic signs a Business Associate Agreement with us before any patient data is processed — it's built into onboarding, signed electronically, and your clinic keeps a copy of the signed record. No BAA, no PHI. It's that simple.

Request the BAA text

Questions about compliance?

Ask us anything — and if your compliance reviewer wants documentation, we'll provide it line by line.

Notermed — CS2 Technologies Inc.
Email: info@notermed.com
Phone: +1 905 749 5338