Skip to content
English
  • There are no suggestions because the search field is empty.

How Does Scribematic Protect Patient Data?

Overview

Privacy, Security and Compliance

This article provides a high-level overview of how Scribematic protects patient data and explains the platform’s approach to privacy, security, and regulatory compliance.

Scribematic is an ambient listening medical scribe designed to securely process clinical encounters into structured medical documentation while protecting patient privacy. The platform is built with safeguards that align with healthcare regulations and industry security standards, enabling providers to confidently use AI-assisted documentation in clinical workflows.


Best Practices and Tips

  • Always obtain patient consent before using AI-assisted scribing, in accordance with local and state regulations.

  • Clearly communicate to patients when recording is taking place.

  • Use Scribematic in secure environments and on trusted devices.

  • Regularly review and verify AI-generated notes before adding them to the medical record.

  • Incorporate Scribematic into your organization’s HIPAA Security Risk Assessment.

  • Follow your organization’s internal policies for documentation and consent tracking.

  • Avoid including unnecessary sensitive information outside the scope of the clinical encounter.


HIPAA & Regulatory Compliance

Scribematic meets the requirements of the Health Insurance Portability and Accountability Act (HIPAA), the primary U.S. regulation governing the protection of Protected Health Information (PHI).

How Scribematic Supports HIPAA Compliance

  • Scribematic operates as a Business Associate when handling PHI on behalf of healthcare providers.
  • The platform adheres to the HIPAA Privacy Rule and Security Rule to safeguard patient information.
  • Security and privacy protections are built into the platform’s infrastructure and workflows.

Clinicians should obtain patient consent when using AI-assisted scribing and should consult their state and local regulations regarding recording requirements.


Security Certifications & Industry Standards

Scribematic aligns with several recognized security and privacy frameworks used across healthcare and enterprise technology.

Compliance Frameworks

Scribematic aligns with the following standards:

  • HIPAA Compliance
  • SOC 2 Type II
  • ISO 27001:2022 Certification
  • CCPA Compliance
  • GDPR Compliance
  • PIPEDA Compliance
  • PHIPA Compliance

These frameworks involve independent audits, third-party verification, and ongoing monitoring to ensure that sensitive healthcare data is properly protected. Visit Scribematic's Trust Center for more information on each of these compliance frameworks.


Encryption & Technical Safeguards

Scribematic uses modern security practices to protect patient data during transmission and storage.

Data Encryption

  • Data is encrypted in transit between user devices and Scribematic servers.
  • Data is encrypted at rest while securely stored in the system.

The diagram below shows the flow of data from the beginning of a recording until it is returned as a completed note. Start at the top left of the chart with "Audio," follow the flow to the right and end with "Usable Medical Note."  This flowchart shows how Scribematic protects PHI throughout the process.



AI Data Usage & Model Training

Scribematic takes a conservative and privacy-first approach when using AI to generate medical documentation.

Patient Data Is Not Used to Train AI Models

Patient visits, recordings, and generated notes are not used to train AI models.

Scribematic does not allow the AI to learn from or retrain itself on patient encounters. This approach helps ensure that sensitive clinical data remains protected and is never incorporated into model training datasets.

Improving Output Without Using Patient Data

Instead of training AI on patient encounters, Scribematic provides tools that allow clinicians to guide and refine the system directly.

These include:

Templates

Providers can create templates that instruct the AI exactly how notes should be structured and written.

Custom Lexicon

The Custom Lexicon allows clinicians to define commonly used terms, medications, names, or phrases so they are documented correctly every time.

“How Could This Note Be Improved” Feedback

Each note includes a “How could this note be improved?” option that sends feedback directly to the Scribematic engineering team. This allows the platform to improve while keeping patient data protected.

Access Control

Only authorized users can access clinical data through secure authentication and controlled user permissions.


Data Retention & Deletion

Recording Retention

  • Recordings are encrypted and temporarily stored for provider review.
  • Recordings are deleted from provider accounts after 30 days.

Final Deletion

  • After removal from accounts, data is held for an additional secure 30 days before permanent deletion.

This approach allows providers sufficient time to finalize documentation while maintaining responsible data retention practices.


Clinician Responsibilities for Compliance

While Scribematic provides a secure platform, clinicians remain responsible for ensuring their own compliance workflows.

Providers Should

  • Obtain appropriate patient consent when required.
  • Review and verify AI-generated documentation before finalizing notes.
  • Include Scribematic in their practice’s HIPAA Security Risk Assessment.

These steps help ensure proper alignment with regulatory requirements and internal compliance policies.


Obtaining Patient Consent for Using Scribematic

Scribematic recommends obtaining patient consent before using AI-assisted medical scribing. Consent can be obtained verbally or in writing as part of standard intake procedures.

Some jurisdictions may require documented consent, so providers should consult local and state regulations.

Example Consent Scripts

Assistant

“Dr. ______ will be using an AI service called Scribematic to help take notes today. Is that OK?”

Provider (concise)

“I’m using an AI scribe to help me take notes. Is that OK?”

Provider (patient-focused)

“To give you my full attention, I’m using a service called Scribematic to help me take notes. It transcribes our visit and creates notes for your medical chart. Is it OK if I use this service during our visit?”


Documenting Consent

When required by local regulations, providers should:

  • Record verbal consent in the patient’s chart
  • Maintain written or electronic consent records
  • Follow their practice’s internal documentation policies

Consent practices should also be incorporated into the practice’s HIPAA Security Risk Assessment.


Security Audits & Accountability

Scribematic maintains ongoing internal and external reviews of its security posture.

Certifications such as SOC 2 Type II and ISO 27001 confirm the presence of strong administrative, physical, and technical safeguards.


Additional Resources

Visit Scribematic's Trust Center for more information.

If you have questions or would like personalized guidance, our team is available to assist you. 

Contact the Scribematic Support team through the in-platform chat icon for assistance or email support@scribematic.ai. 

Schedule a free one-on-one Zoom product walk through: Schedule Demo Here


[Link to troubleshooting guide for deleted notes]