Skip to main content
Privacy & HIPAA

Privacy, HIPAA, and AI processing

How BxScribe handles PHI, encryption, business associate agreements, and AI vendor data flow.

Updated October 2, 2026

Encryption and access

Client data is encrypted in transit with TLS and at rest by our database and file-storage providers. Only signed-in users whose role or active assignment allows it can read a given client's records.

Sessions sign out after an hour without activity, in every tab, and every session ends 24 hours after sign-in. You can add two-factor sign-in under Settings → Security, and agency owners can require it for everyone.

Deleting your account takes effect after 30 days and removes your sign-in and personal workspace, including uploaded files. Records you created for an agency stay with that agency, finalized notes are never deleted (corrections are amendments), and audit records are kept for seven years.

Business Associate Agreements (BAA)

We are putting our Business Associate Agreement and our sub-processor agreements in place and don't offer a BAA yet. If your organization needs one, send a HIPAA & BAA inquiry from the contact page and we'll follow up when it's available. The Security & HIPAA page lists the safeguards in place today.

Still stuck?

Open a ticket and we'll help directly.

Open a ticket

More from Privacy & HIPAA