We enforce administrative, physical, and technical controls to secure patient healthcare information (PHI) at rest and in transit.
| Safeguard Rule | HIPAA Specification | TherapyScribe AI Implementation Controls |
|---|---|---|
| Administrative (§164.308) |
Risk analysis, user training, and information access policies. | Staff training protocols, role-based access control, periodic security reviews, and signed Business Associate Agreements (BAA) with all clients. |
| Physical (§164.310) |
Facility access limits, device policies, and server hardware protections. | Isolated data hosting in AWS secure facilities with physical guards, access logs, and biometrics. Server rooms restricted to hosting personnel. |
| Technical (§164.312) |
Access control, audit trails, transmission security, and integrity seals. | AES-256 database encryption, TLS 1.3 transit pathways, Multi-Factor Authentication (MFA), and cryptographic SHA-256 note verification. |
We retain note histories to compile clinic analytics. Upon contract termination, all associated patient records are permanently deleted from database clusters within 30 days. Backup files are overwritten and fully purged after 90 days.
If a data breach is detected, our Incident Response Team isolates affected containers within 2 hours. In compliance with HIPAA rules, all affected clients and clinics will be notified within 72 hours of verification.
As a Mumbai-registered entity, **CORESTYL AI PRIVATE LIMITED** complies with India's DPDPA 2023. We act as a Data Processor for healthcare clinics (Data Fiduciaries). We process Indian patient records locally, obtaining strict consent through registered clinics and maintaining full consent logs.
Our standard Business Associate Agreement outlines the legal responsibilities of both parties. Key terms:
| Sub-Processor Entity | Location / Registry | Service Purpose |
|---|---|---|
| Amazon Web Services (AWS) | United States / India Nodes | Secure VPC hosting, encrypted databases, and KMS key management. |
| CoreStyl AI LLM Cluster | India Private Nodes | Fine-tuned clinical vocabulary and entity extraction parsing. |
If you discover a security vulnerability in our platform, please report it to our security team immediately. We investigate all disclosures.