Security & Compliance

Comprehensive security measures and HIPAA compliance framework designed to protect patient data and dental practices.

HIPAA Security Framework

SideScribe implements a comprehensive security program aligned with HIPAA Security Rule requirements, combining administrative, technical, and physical safeguards to ensure the confidentiality, integrity, and availability of protected health information.

Administrative Safeguards

Policies and procedures that govern workforce operations and data handling.

Technical Safeguards

Code-level protections and access controls for data security.

Data Lifecycle

Procedures for handling, processing, and destruction of patient data.

Section 1: Administrative Safeguards

Internal policies that govern how the workforce operates.

1.1 Risk Management Policy

Annual audit process for Azure/OpenAI infrastructure, including vulnerability assessments, penetration testing, and security control effectiveness reviews.

1.2 Sanction Policy

Disciplinary guidelines for HIPAA violations, including progressive discipline procedures, mandatory reporting requirements, and corrective action plans.

1.3 Security Training Log

Record of founder's HIPAA certification and annual security awareness training, including completion dates, training topics, and assessment results.

1.4 Information System Review

Schedule for weekly audit log checks, including automated monitoring alerts, manual review procedures, and escalation protocols for suspicious activities.

Section 2: Technical Safeguards

Descriptions of the code-level protections built into the system.

2.1 Access Control Policy

Unique User IDs with role-based access controls, automatic log-off after 15 minutes of inactivity, and forced multi-factor authentication for all user sessions.

2.2 Audit Control Logic

Description of immutable audit logs capturing Who, What, When, and Where for all system activities, with tamper-proof storage and automated retention policies.

2.3 Data Integrity Plan

API rate-limiting and payload validation procedures to prevent data corruption, including input sanitization, schema validation, and checksum verification.

2.4 Transmission Security

TLS 1.3 encryption standards for all data-in-transit, with perfect forward secrecy, certificate pinning, and automated certificate renewal procedures.

Section 3: Data Lifecycle

Procedures for the handling and destruction of patient data.

3.1 Zero Data Retention Policy

Formal declaration of immediate data purging after clinical note generation, ensuring no audio recordings or raw data persist beyond the active session.

3.2 Backup & Destruction Procedure

Scripted deletion of metadata after 7 days, with automated cleanup procedures and manual verification processes to ensure complete data removal.

3.3 Media Disposal Policy

Procedures for secure wiping of local devices if retired, including cryptographic erasure methods and certificate of destruction documentation.

Section 4: External Agreements

Contracts with patients, partners, and vendors.

4.1 Downstream Business Associate Agreements

Signed agreements with Microsoft (Azure) and OpenAI, establishing their obligations as business associates under HIPAA and ensuring chain of trust compliance.

4.2 Customer Business Associate Agreement

The standard BAA template provided to all dental practices, outlining mutual responsibilities and liability for protected health information.

4.3 Patient Informed Consent

Robust consent form for Illinois dental offices, explaining recording procedures, data handling practices, and patient rights under HIPAA.

4.4 Privacy Policy & Terms of Service

Public-facing website documentation outlining data practices, user rights, and service terms for all customers and users.

Section 5: Emergency & Incident Response

What happens when things go wrong.

5.1 Incident Response Plan

5-step checklist for breach containment: (1) Detection and Assessment, (2) Containment, (3) Eradication, (4) Recovery, and (5) Post-Incident Review.

5.2 Disaster Recovery Plan

Procedures for service restoration via Azure geo-redundant backups, including recovery time objectives, backup verification, and failover testing.

5.3 Breach Notification Template

Pre-written notification letter for alerting affected dental practices of security events, including required HIPAA elements and communication timelines.

Questions About Security?

Our security measures are designed to protect both patient data and your practice. For specific security inquiries, please contact our compliance team.

Contact Compliance Team