AutoNotes maintains two separate policy frameworks to ensure clarity for users, regulators, and automated systems:
Website Environment
The public site at autonotes.ai and related marketing pages fall under the Website Privacy Policy and Website Terms of Service. These govern non-clinical interactions such as viewing content, submitting contact forms, or engaging with chat features. No PHI should ever be entered or transmitted through these pages.
Application Environment
The secure platform at app.autonotes.ai is governed by the Application Privacy Policy, Application Terms of Service, BAA, and EULA. These documents explicitly authorize the storage and processing of PHI within a HIPAA-aligned program. PHI use is permitted under a signed BAA (executed at signup or prior to PHI use) and includes Clients (PHI-enabled client profiles and features).
By maintaining clear boundaries between the public website and the secure application, AutoNotes ensures that public marketing content remains outside the scope of HIPAA while the product itself operates under stringent compliance controls.
Security-by-Design Controls
PHI & AI/LLM Safeguards
Framework Alignment. Our program aligns with:
Transparency & Documentation. You can review all AutoNotes compliance and security documents anytime through the AutoNotes Trust Center, including:
AutoNotes supports HIPAA aligned workflows and international privacy frameworks.
AutoNotes AI is production ready and governed by documented controls across privacy, security, and model quality.
Purpose and scope: AI features assist with clinical documentation including draft notes, summaries, plan suggestions, and workflow automation. AI outputs are assistive and the clinician remains the final reviewer.
Data handling and privacy: AI requests may contain PII or PHI. Data is processed under BAA and DPA, encrypted in transit and at rest, and protected by RBAC, SSO, and MFA. Customer data is not used to train models without explicit agreement.
Model providers and isolation: Requests are logically isolated per tenant. No cross customer data mixing occurs. Subprocessors are vetted, reviewed, and access is restricted and audited.
Logging and auditability: All AI invocations are audit logged with metadata while minimizing PHI exposure.
Quality and safety: Evaluation systems monitor accuracy, relevance, and safety. Clinicians must review outputs before finalizing.
Responsible AI: Monitoring is in place for bias and hallucination risk with reporting and incident response processes.
SDLC and change control: Prompts and pipelines follow structured testing, review, and controlled rollout processes.
Data retention: AI data follows customer retention settings with support for de-identified workflows.
Customer controls: Role based permissions, feature toggles, and export capabilities are available.
The AutoNotes Configuration and Asset Management Policy establishes mandatory controls for asset inventory, ownership, baseline secure configurations, change authorization, and ongoing maintenance of all systems handling customer data or PHI.
This program ensures systems are consistently monitored, securely configured, and maintained in alignment with HIPAA, PHIPA, and SOC 2 requirements.
OpenAI
Deepgram
Cloudflare
Twilio
Intercom
Sentry
Stripe
SafeBase
ActiveCampaign
LiveKit
Essential cookies are always on. Optional cookies for analytics, functionality, and advertising are only used if you allow them. You can change your preferences at any time in Cookie Settings.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
Google Tag Manager simplifies the management of marketing tags on your website without code changes.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
Clarity is a web analytics service that tracks and reports website traffic.
Service URL: clarity.microsoft.com (opens in a new window)
Marketing cookies are used to follow visitors to websites. The intention is to show ads that are relevant and engaging to the individual user.
Google Ads is an online advertising platform that enables businesses to create targeted ads displayed on Google search results and partner sites.
Service URL: policies.google.com (opens in a new window)
TikTok Pixel is a tracking tool that measures user interactions and optimizes ad campaigns on the TikTok platform.
Service URL: ads.tiktok.com (opens in a new window)