Skip to main content
Trust

Security & HIPAA

BxScribe is built for clinical documentation, so the safeguards below apply to every account on every plan. This page lists the controls that are in place today.

Last updated: September 24, 2026

Technical safeguards

Encryption in transit

Every connection to BxScribe uses TLS (HTTPS). Session cookies are host-only, so the clinician app and each family portal keep separate sessions.

Encryption at rest

The database is encrypted at rest by our managed Postgres provider. Uploaded files are stored in Amazon S3 with server-side AES-256 encryption and are only served through short-lived signed links.

Verified sign-in

Email-and-password accounts must confirm their address before they can sign in. Password-reset links expire after one hour and resetting a password signs out every other session. Google sign-in is also available.

Automatic sign-out

After 15 minutes without activity you are signed out, in every open tab, so an unattended screen doesn't keep showing client records.

Role- and assignment-based access

Each agency's data is separated at the query layer. Clinicians see only the clients actively assigned to them; owners and admins decide who else sees what, and billing staff never see note content.

Audit logging

Sign-ins, record views, changes, exports and team changes are written to a server-side audit log with the actor, time and IP address. Agency owners, admins and compliance staff can review and export it in the app. Audit entries are kept for seven years.

Data retention controls

You choose how long session notes are kept (1, 3, 5 or 7 years, or indefinitely) in Settings. A daily job removes notes past that period.

Export and deletion

You can export your data at any time. When you delete your account, your personal data and notes are permanently removed within 30 days.

Business Associate Agreements

An ABA agency is a HIPAA covered entity, and a vendor that stores its clinical records is a business associate. We are putting our own Business Associate Agreement and the agreements with our sub-processors in place; until that work is finished we don't offer a BAA. The current status of each vendor is on the sub-processors page. If your organization needs a BAA, tell us through the contact form (topic “HIPAA & BAA inquiry”) and we'll follow up when it is available.

AI processing

Drafting features send the session details you enter to OpenAI to generate text. We recommend identifying clients by initials or a code rather than full names. Every AI draft is a starting point that a clinician reviews, edits and signs; it does not replace clinical judgment.

Your responsibilities

  • Keep your password private and sign out on shared devices.
  • Give team members the least access their job needs, and remove people who leave.
  • Review AI-drafted content before you sign or submit it.

Reporting a vulnerability

If you believe you've found a security vulnerability or a privacy issue, email security@bxscribe.com with enough detail for us to reproduce it. Please don't access other people's data or disrupt the service while testing, and give us a reasonable chance to fix the issue before disclosing it.

Related