Security & compliance
MediScribe Flow is a clinical documentation workflow platform designed to support HIPAA-aligned workflows for hospice, home health, and other field-based clinical teams. Security and privacy are foundational to how the product is built — from capture in the field through secure delivery. This page summarizes our approach. We're glad to provide more detail and a Business Associate Agreement (BAA) for your organization.
Our principles
- Practitioner-controlled review. Documentation is reviewed and approved by a practitioner before it is finalized or delivered. Nothing is sent automatically without review.
- Clinical responsibility stays with the practitioner. MediScribe Flow provides documentation workflow support and review assistance — including OASIS-E2-oriented review where configured. The practitioner remains responsible for clinical judgment, review, and final documentation, and OASIS assessments are not submitted automatically.
- Minimum necessary. Patient information is handled with a minimum-necessary approach throughout the workflow. Examples shown on our marketing site use sample data only.
- Defense in depth. We combine encryption, access controls, authentication, and audit logging rather than relying on any single safeguard.
Data protection
- Encryption in transit. Information is transmitted over encrypted connections (TLS).
- Encryption at rest. Stored information is encrypted at rest in our cloud infrastructure.
- No raw audio or transcripts retained. We don't keep raw audio or transcripts on our servers — the reviewed documentation is the retained output. Voice recordings are deleted from our servers promptly after processing.
- On-device protection. On mobile, PHI is encrypted at rest on the device. When the app is offline, voice recordings are stored locally in encrypted form and removed once they have been uploaded for processing.
- App protections. An optional biometric app lock and an automatic session timeout after inactivity help keep an unattended device from exposing PHI.
AI processing
- Processed under a BAA, with Zero Data Retention. Transcription and document drafting are performed by a third-party AI provider engaged under a Business Associate Agreement (BAA) with Zero Data Retention — your content is not retained by the AI provider after the request is processed, is not used to train its models, and is not used for advertising or marketing profiling.
- You approve first. The app asks for the practitioner's approval before any clinical content is sent for processing, and the disclosure is available in the app at any time.
No tracking or analytics
- No analytics, cookies, or advertising. Neither this website nor the apps use analytics, cookies, or advertising or tracking SDKs. We don't track you across other apps or sites, and we don't sell data.
Access & authentication
- Standards-based authentication. Sign-in uses industry-standard OAuth 2.0 / PKCE flows; we do not store passwords.
- Role-based, least-privilege access. Administrators govern which templates and customers are available and who can receive documents, and each member sees only what their role needs.
- Recipient controls. Delivery is controlled, with recipient access managed by your organization.
Oversight & accountability
- Audit logging. Key actions are logged to support operational oversight and accountability.
- Administrator governance. Organizations manage templates, access, and recipients centrally.
HIPAA & Business Associate Agreements
MediScribe Flow is designed to support HIPAA-aligned documentation workflows, with administrative, physical, and technical safeguards, and we have executed Business Associate Agreements with the subprocessors that handle PHI on our behalf. If your organization operates as a HIPAA-covered entity or business associate, we provide a Business Associate Agreement (BAA). Please contact us at support@mediscribeflow.com to put a BAA in place before using the Service with protected health information (PHI).
As described in our Privacy Policy, customers remain responsible for ensuring their use of the Service complies with HIPAA, applicable state privacy laws, and their organization's policies.
Data retention & deletion
Voice recordings are deleted from our servers promptly after processing is complete. You can clear the app's locally cached data on a device at any time from the app — this clears the local cache on that device only, while the authoritative record is retained server-side by the covered entity in accordance with applicable retention obligations — and you can request deletion of your account and associated data by emailing support@mediscribeflow.com. See our Privacy Policy and Account Deletion page for details.
Reporting a security concern
If you believe you have found a security vulnerability or have a security question, please contact us at support@mediscribeflow.com with the subject "Security inquiry." We take reports seriously and will respond promptly.