Skip to main content
Privacy & HIPAA

Privacy, HIPAA, and AI processing

How BxScribe handles PHI, encryption, business associate agreements, and AI vendor data flow.

Updated May 9, 2026

Encryption and access

All client data is encrypted at rest in our PostgreSQL database and in transit via TLS. Only authenticated users with a workspace assignment can read a given client's records.

Idle sessions automatically time out. Account-level deletion permanently removes all PHI within 30 days of request.

Business Associate Agreements (BAA)

Agency customers can request a BAA at support@bxscribe.com. We'll send a standard template covering BxScribe and our subprocessors.

Still stuck?

Open a ticket and we'll help directly.

Open a ticket