Encryption and access
Client data is encrypted in transit with TLS and at rest by our database and file-storage providers. Only signed-in users whose role or active assignment allows it can read a given client's records.
Sessions sign out after an hour without activity, in every tab, and every session ends 24 hours after sign-in. You can add two-factor sign-in under Settings → Security, and agency owners can require it for everyone.
Deleting your account takes effect after 30 days and removes your sign-in and personal workspace, including uploaded files. Records you created for an agency stay with that agency, finalized notes are never deleted (corrections are amendments), and audit records are kept for seven years.
AI processing consent
When you generate a note, we send the session details you enter, the client's first name and relevant profile fields to OpenAI to draft the text. Dictation and live sessions send audio for transcription — BxScribe keeps the transcript, not the audio. Our sub-processors page lists every vendor and its Business Associate Agreement status.
The date you gave AI-processing consent is shown in Settings → Profile. To withdraw it, contact support@bxscribe.com.
Business Associate Agreements (BAA)
We are putting our Business Associate Agreement and our sub-processor agreements in place and don't offer a BAA yet. If your organization needs one, send a HIPAA & BAA inquiry from the contact page and we'll follow up when it's available. The Security & HIPAA page lists the safeguards in place today.

