Compliance

Built for controlled documentation workflows

Clinic Notes AI is clinician-facing documentation support — not a therapy bot, not a patient chatbot, not autonomous care. Here is how we approach compliance.

What Clinic Notes AI does

  • Records or accepts uploaded session audio after consent is documented
  • Generates transcripts from that audio
  • Optionally drafts notes and structured EHR fields from the transcript
  • Requires clinician review and sign-off before anything enters the EHR

What Clinic Notes AI does not do

Clinic Notes AI is not designed to diagnose patients, provide therapy, deliver emotional support, act as a crisis chatbot, or autonomously make clinical decisions. This boundary is intentional — it keeps the product in the lower-risk documentation category rather than the higher-risk therapeutic communication category.

Consent is a product control

AI-assisted documentation is blocked until patient consent is recorded in the application. The consent workflow includes distinct handling for 42 CFR Part 2 applicability. Consent activity is audit-labeled.

Clinician review is mandatory

Clinic Notes AI does not assume AI output is error-free. Transcripts, extracted fields, and drafted notes can contain errors or omissions. All generated output is labeled AI-GENERATED — REVIEW REQUIRED and must be reviewed, edited, and approved by the licensed clinician before use in the medical record.

Vendor and BAA status

We maintain Business Associate Agreements with our infrastructure vendors. Current status:

  • OpenAI — BAA executed for HIPAA-eligible transcription (Zero Data Retention)
  • Anthropic — BAA in progress for note generation and structured extraction
  • Supabase, Vercel — HIPAA add-ons available, activation tracked

We believe compliance trust is earned by showing both controls and open gaps clearly. We provide a vendor transparency packet, subprocessor list, and current BAA status during diligence.

Architecture controls

  • Transcript-first workflow — the transcript is always available before any note generation
  • Row-level tenant isolation on all application data
  • PHI-avoidant logging — logs record job IDs and status, not transcript content
  • Audit event model covering consent, job lifecycle, and clinical actions
  • Kill switch for AI vendor calls independent of application deployment

Frequently asked questions

Is Clinic Notes AI a therapy bot?

No. It is a clinician-facing documentation workflow. It does not interact with patients.

Does the clinician stay responsible for the note?

Yes. The clinician reviews, edits, and decides what enters the EHR. AI output is treated as a draft, not a final record.

Can this replace clinical judgment?

No. Clinic Notes AI is documentation support software, not a clinical decision-maker.

Does Clinic Notes AI support 42 CFR Part 2?

The consent workflow includes distinct handling for Part 2 applicability. Specific segmentation and re-disclosure controls should be evaluated against your organization’s Part 2 obligations during pilot planning.

Are all vendor BAAs complete?

Not yet across the full stack. OpenAI coverage for transcription is complete. Additional vendor and infrastructure coverage items are tracked explicitly and disclosed during diligence.

For a copy of our vendor transparency packet, subprocessor list, or diligence one-pager, contact us directly.

Request diligence materials