TS
TherapyScribe AI
COMPLIANCE VERIFICATION

Security & HIPAA Compliance

We enforce administrative, physical, and technical controls to secure patient healthcare information (PHI) at rest and in transit.

HIPAA Aligned
Verified
SOC 2 Type I
Roadmap (Q3 2027)
ISO 27001
Roadmap (Q4 2027)
AWS Architected
Verified
Safeguard Rule HIPAA Specification TherapyScribe AI Implementation Controls
Administrative
(§164.308)
Risk analysis, user training, and information access policies. Staff training protocols, role-based access control, periodic security reviews, and signed Business Associate Agreements (BAA) with all clients.
Physical
(§164.310)
Facility access limits, device policies, and server hardware protections. Isolated data hosting in AWS secure facilities with physical guards, access logs, and biometrics. Server rooms restricted to hosting personnel.
Technical
(§164.312)
Access control, audit trails, transmission security, and integrity seals. AES-256 database encryption, TLS 1.3 transit pathways, Multi-Factor Authentication (MFA), and cryptographic SHA-256 note verification.
ENVELOPE ENCRYPTION ARCHITECTURE
Edge Device
Audio Ingestion
Local Buffer
➔ TLS 1.3 ➔
AWS VPC Transit
Web Application Firewall
API Gateway
➔ AES-256 ➔
Isolated Tenant DB
Envelope Encryption
AWS KMS Keys
Security Mechanisms:
* Transit: Raw audio is encrypted at the device layer using Web Crypto APIs before being sent over TLS 1.3 to AWS endpoint clusters.
* Storage: Database records are encrypted using unique data keys managed by AWS Key Management Service (KMS), rotating keys automatically.
* Isolation: Each clinic's records are logically isolated in dedicated database tenants, preventing cross-organization access.
POL-01 // PHI RETENTION

PHI Retention & Deletion

We retain note histories to compile clinic analytics. Upon contract termination, all associated patient records are permanently deleted from database clusters within 30 days. Backup files are overwritten and fully purged after 90 days.

POL-02 // INCIDENT RUNBOOK

Breach Notification Runbook

If a data breach is detected, our Incident Response Team isolates affected containers within 2 hours. In compliance with HIPAA rules, all affected clients and clinics will be notified within 72 hours of verification.

POL-03 // REGIONAL COMPLIANCE

India Digital Personal Data Protection Act (DPDPA) 2023 Alignment

As a Mumbai-registered entity, **CORESTYL AI PRIVATE LIMITED** complies with India's DPDPA 2023. We act as a Data Processor for healthcare clinics (Data Fiduciaries). We process Indian patient records locally, obtaining strict consent through registered clinics and maintaining full consent logs.

CORESTYL AI BAA SUMMARY

Our standard Business Associate Agreement outlines the legal responsibilities of both parties. Key terms:

Permitted Uses: We process PHI data only to generate clinical documentation as requested by the clinic. We do not sell or monetize patient data.
Sub-Contractors: Any sub-processors we use must agree to the same security standards and BAA protections.
Clinic Auditing Rights: Clients have the right to request annual security summaries and access log reports.
Sub-Processor Entity Location / Registry Service Purpose
Amazon Web Services (AWS) United States / India Nodes Secure VPC hosting, encrypted databases, and KMS key management.
CoreStyl AI LLM Cluster India Private Nodes Fine-tuned clinical vocabulary and entity extraction parsing.
SECURITY DISCLOSURES

Responsible Vulnerability Disclosure

If you discover a security vulnerability in our platform, please report it to our security team immediately. We investigate all disclosures.

Contact: security@corestyl.com