Built with patient privacy as a design requirement
Every architectural decision in Scribemarrow starts with the question: what's the minimum data we need to handle, for the shortest possible time? Audio is not retained after processing. Notes live in your EHR, not ours.
HIPAA-by-Design
Controls built in, not bolted on
BAA Included
All tiers, executed at onboarding
AES-256 Encryption
Data in transit and at rest
US Data Residency
All processing on US infrastructure
Audit Logging
Full access logs for practice admins
Security at every layer
Audio is not retained
Session audio is processed in real time and deleted immediately after transcription completes. There is no audio archive, no recording playback, and no audio stored in Scribemarrow's infrastructure after the session ends.
Notes live in your EHR
The only persistent copy of a Scribemarrow-generated note is the one delivered to your EHR. Scribemarrow does not maintain a separate note database. Your EHR's own access controls govern who can view patient notes.
Encryption in transit and at rest
All data transmissions use TLS 1.3. Any temporary data held during session processing is encrypted with AES-256. Encryption keys are managed with hardware security modules and rotated on a regular schedule.
Access controls and authentication
Every Scribemarrow session is tied to an authenticated provider credential. Practice administrators can provision and deprovision providers, review access logs, and configure session policies from the admin dashboard.
US-based infrastructure
All processing, temporary storage, and delivery happens on US-based cloud infrastructure. PHI does not transit international boundaries. Scribemarrow uses HIPAA-eligible cloud services with appropriate controls in place.
BAA and compliance documentation
A Business Associate Agreement is executed with every Scribemarrow customer at onboarding. Our security documentation, data flow diagrams, and sub-processor list are available to Group tier practices and their compliance teams on request.
What patients should know about ambient recording
Transparency with patients is a clinical and ethical obligation. Scribemarrow provides guidance on how to discuss ambient documentation with patients.
Our recommended disclosure approach
We recommend practices inform patients at check-in that a documentation assistant may be used during their visit. Most practices add a brief notice to their intake forms and have a standard verbal statement the physician uses at visit start.
The key facts patients generally want to know: the audio is used only to generate the chart note, it is not retained after the note is created, and they can request documentation without ambient capture if they prefer.
Scribemarrow provides sample consent language and staff training materials to all customers during onboarding.
Questions about our security posture?
Our team is available to answer compliance and security questions for practices in evaluation. Group tier practices can request a full security review package.