Security and compliance

Protect every clinical note

ClinicFrame gives your practice the controls, agreements, and infrastructure required to use AI with protected health information.

The visit

Visit audio is discarded

ClinicFrame processes visit audio to create the transcript, then discards the audio. Your clinical documentation remains available in your account.

Encryption in transit and at rest

TLS protects data in transit. Encryption at rest protects stored transcripts, notes, and patient records.

Your account

HIPAA compliant, BAA included

A Business Associate Agreement is included with every account, including the Free plan. Complete it before entering patient information.

Role-based access

Sign-in and access controls protect the clinical information in each clinician's account.

Patient content stays out of training

ClinicFrame does not use patient content to train AI models. Our provider agreements carry the same restriction.

How we operate

Protected cloud infrastructure

ClinicFrame runs clinical workloads on cloud infrastructure configured for HIPAA-regulated data.

Access logging and monitoring

ClinicFrame logs access to clinical data and monitors system activity for security events.

Documented incident response

Our incident response process covers investigation, containment, recovery, and required breach notifications.

Not ready to try it yet? Talk to us first.

Tell us what you’re trying to solve. Someone from the team writes back.

FAQs

Frequently Asked Questions

Straight answers about how ClinicFrame works, day to day.

Is ClinicFrame HIPAA compliant?

Yes. ClinicFrame runs on HIPAA-compliant infrastructure. A Business Associate Agreement is included with every account, including the Free plan.

Do you store the audio from patient visits?

No. ClinicFrame processes visit audio and discards it. Your account retains the transcript, notes, and patient information used in your documentation workflow.

How is my data encrypted?

ClinicFrame encrypts data in transit with TLS and encrypts stored data at rest. These controls protect transcripts, notes, and patient records throughout the documentation workflow.

Who can access patient data in ClinicFrame?

ClinicFrame requires you to sign in, applies access controls, and logs access to clinical data. Each clinician works in their own account.

Does ClinicFrame train AI models on my patients' data?

No. ClinicFrame does not use patient content to train AI models. Our agreements with transcription and AI providers exclude customer content from model training.

What happens if there's a security incident?

We maintain a documented incident response plan with breach notification aligned to HIPAA timelines.

Extra hours aren’t supposed to follow you home.
ClinicFrame keeps them at the clinic.

Try it for free