How we protect patient data.
What we collect, what we discard, how the record is encrypted, and who can see it.
Session audio is not stored.
Most clinical AI records the session and keeps the file. We do not. Speech is transcribed in memory, the words carry forward into the record, and the recording is dropped where it was made.
No recording archive
Audio is transcribed and then discarded. There is no library of session recordings on our systems.
Consent before the microphone
Capture is opt-in per patient. Turn it off and everything else still works.
The same rule in the journal app
Speech becomes text you can edit. The audio is not retained.
Records are held under a code, not a name.
Identifiers are removed on the way in, including inside free text, where they usually survive.
The filter runs before storage, not after. In our database a patient is a code, and the identity behind it stays encrypted.
Four layers around one record.
Four controls, each assuming the one outside it has already failed.
- 1NetworkTLS in transit, private cloud isolation
- 2StorageEncrypted at rest, encrypted backups
- 3IdentityPatients held as encrypted identities
- 4AccessScoped roles, every read logged
Every clinical decision stays with the clinician.
Empaithy highlights patterns for review. It does not diagnose or predict a crisis, and nothing enters the chart without a person approving it.
Sub-processors.
Third-party AI and infrastructure providers help run the service, and data may be processed outside your country. The list is current, and you are told before it changes.
Each vendor is named in the data processing agreement.
Compliance and agreements.
HIPAA-ready with a BAA, GDPR-aligned with a DPA, SOC 2 Type II in progress.

Questions about security?
Write to us and the right person on our team will answer.