PodScribe Security & HIPAA Compliance

Last Updated: September 11, 2026 (Ambient AI Scribe Governance section added)

PodScribe is a HIPAA-compliant AI clinical scribe built exclusively for podiatric medicine. Every component — from voice transcription to note generation to data storage — is designed to protect patient data without compromise. This page details exactly how.

AI & Your Data

  • All AI processing uses HIPAA-compliant Azure OpenAI services with a signed Business Associate Agreement (BAA).
  • Your transcripts and clinical notes are never used to train AI models — ever.
  • No patient data is retained by AI services after processing is complete.
  • Proprietary podiatry-specific prompts are stored server-side and never exposed to the browser or client.
  • All AI-generated content, including clinical notes, billing codes, compliance analyses, and document analyses, is provided as a drafting aid only. The licensed provider is solely responsible for reviewing, verifying, and approving all output before use in any medical record or billing submission.

PHI De-Identification Technology

  • PodScribe uses a proprietary, enterprise-grade de-identification engine that automatically strips Protected Health Information (PHI) before any data reaches the AI.
  • 11 categories of PHI are automatically detected and replaced with non-identifying tokens: patient names, dates of birth, Social Security numbers, phone numbers, email addresses, street addresses, insurance member IDs, claim numbers, group numbers, medical record numbers, and account numbers.
  • Dates of birth are intelligently replaced with calculated patient age to preserve clinical relevance during AI processing.
  • De-identification runs automatically before every AI API call across all AI-powered features, including note generation, compliance auditing, billing analysis, document analysis, and EHR mapping.
  • AI models never receive, process, or store real patient identifiers. Original values are restored only in the final output delivered to the provider.
  • All de-identification operations are audit-logged for HIPAA compliance tracking.

Learn more about our PHI protection technology →

Encryption & Data Protection

  • All data encrypted at rest using AES-256 and in transit using TLS 1.2+.
  • Voice transcription uses enterprise-grade, end-to-end encrypted Azure Speech Services.
  • Cryptographic modules conform to FIPS PUB 140-2 standards.
  • All processing occurs on US-based Azure data centers (Arizona and Virginia) — your data never leaves the country.

Cloud Infrastructure & Availability

  • Hosted entirely on Microsoft Azure with a signed HIPAA Business Associate Agreement.
  • Continuous data replication across availability zones for point-in-time recovery.
  • Azure's high-availability infrastructure ensures your data is always accessible.
  • Annual disaster recovery testing through tabletop and technical exercises.
  • Backups are encrypted and stored securely within the US.

Security Certifications & Compliance

  • SOC 2 Type I and Type II compliant.
  • HIPAA compliant with signed BAAs across all vendors who process patient information.
  • Aligns with OWASP secure coding standards.
  • Regular security audits, risk assessments, and third-party vulnerability assessments.
  • Azure Security Center used for continuous monitoring and vulnerability scanning.

User Access & Management

  • Role-based access control with unique user IDs and strong password requirements (12+ characters, bcrypt hashed).
  • Two-factor authentication required for all internal personnel.
  • Immediate access revocation upon employment termination or policy violation.
  • Annual access reviews to verify proper authorization levels.
  • All company workstations use encrypted hard drives and enforced access controls.

Network & Firewall Security

  • All connections terminate at a firewall; rules reviewed and updated quarterly.
  • Stateful packet inspection via Azure Network Security Groups.
  • Network segmentation separates databases from front-end systems.
  • Continuous 24/7 monitoring using Azure Monitor for events, traffic, and logs.

Secure Development Lifecycle

  • Security integrated into every stage of the development pipeline (DevSecOps).
  • Adherence to industry-standard secure coding guidelines.
  • Static and dynamic application security testing throughout development.
  • Automated security scans of codebase and infrastructure.
  • All software changes reviewed for compliance before deployment.
  • Infrastructure-as-code: all infrastructure changes reviewed before deployment.

Incident Response & Monitoring

  • Documented incident response plan with notification and mitigation procedures.
  • 24/7 continuous monitoring via Azure Monitor.
  • Regular security audits and third-party assessments.
  • Prompt patch management based on vulnerability assessments with structured approval process.

Internal Personnel Security

  • Background checks required for all employees before hiring.
  • Annual security awareness training covering HIPAA, privacy, and information classification.
  • Role-specific incident response and contingency training.
  • All employees acknowledge understanding of security policies and best practices.

Vendor Management

  • All vendors who process patient information are required to be HIPAA compliant and sign BAAs with PodScribe.
  • Regular review of vendor security practices to ensure continued high standards.

Ambient AI Scribe Governance

Ambient AI scribing reduces documentation burden and introduces privacy, consent and documentation-integrity risks that have to be managed on purpose. PodScribe adopts the positions below as its own stance and builds them into its defaults, its consent forms and its guidance to practices. A physician may choose differently where the product offers a choice; this is what PodScribe recommends.

  • Meaningful consent before recording. A written disclosure and consent at intake, and a verbal disclosure to everyone in the room at every visit before recording starts. A decline is honored without penalty: the patient is seen and documented another way, the decision is recorded, and the chart carries a "do not record" flag the clinician sees at the moment they would press record.
  • Only the signed note is the legal medical record. The audio recording, the transcript and the AI-generated draft are not part of the designated record set. The audio is never stored; the transcript is working material, excluded from record exports; the draft becomes a record only when the clinician reviews, edits and signs it.
  • Disclosed retention. Audio: never stored. Transcript: the practice's own choice in Settings, disclosed to patients on the consent form. A practice may keep transcripts or have them removed, and PodScribe does not advise which to pick. Deletions and retention purges are audit-logged so they are verifiable.
  • The clinician's review is the safeguard. Every note is signed individually, from the note, behind a written attestation that it was reviewed in its entirety and corrected. There is no automatic or batch signing. Signed notes lock; corrections are append-only addenda.
  • Continuity without the scribe. A note can always be produced without a recording -- typed or dictated context, template builders, or a note entered afterward -- so care never waits on the tool and an opt-out costs the patient nothing.
  • Records requests go to the practice. The practice is the covered entity and record custodian. PodScribe, as Business Associate, refers any subpoena, discovery or records request it receives to the practice and acts only on its direction or as the law requires.
  • Reviewed annually. PodScribe re-examines this stance, its consent language and its retention defaults at least once a year as state law, vendor terms and regulatory guidance evolve.

Adopt the written AI Scribe Governance Policy for your practice →  |  Patient consent form →

Questions about our security practices? support@podiatry-scribe.com