Encrypted in transit and at rest
Patient information is encrypted during transmission and while stored, including applicable backups.
Trust at ToothNote.ai
ToothNote.ai signs a Business Associate Agreement with customer practices and uses administrative, technical, and contractual safeguards to protect patient information. Clinicians review and approve every clinical document before it is used or delivered.
Safeguards
These are the public facts a practice needs before beginning a deeper review.
Patient information is encrypted during transmission and while stored, including applicable backups.
Passwordless authentication and role-based access controls help ensure users can reach only the information appropriate to their practice and role.
Hosted on a SOC 2 Type II audited cloud platform eligible for HIPAA workloads. That audit applies to the hosting platform, not to ToothNote.ai as a company.
Relevant account and clinical-document activity is recorded to support security, operational, and compliance review.
Encrypted backups and documented recovery procedures support service continuity.
ToothNote.ai provides a Business Associate Agreement to customer practices and maintains appropriate agreements with subprocessors that handle PHI.
AI and your data
Customer PHI is not used to train shared foundation models.
AI-generated clinical content remains a draft until a clinician reviews and approves it.
Providers that process PHI for ToothNote.ai are governed as subprocessors under appropriate contractual and security requirements.
Common questions
Yes. ToothNote.ai is HIPAA compliant.
Yes. ToothNote.ai provides a Business Associate Agreement to customer practices and maintains appropriate agreements with subprocessors that handle PHI. Email hello@toothnote.ai to request it along with the security overview and applicable subprocessor information.
No. Customer PHI is not used to train shared foundation models.
ToothNote.ai is hosted on a SOC 2 Type II audited cloud platform eligible for HIPAA workloads. That audit applies to the hosting platform, not to ToothNote.ai as a company. We state the distinction plainly rather than implying a company-level certification we do not hold.
Access is controlled by role. Passwordless authentication and role-based access controls help ensure users can reach only the information appropriate to their practice and role.
Security review
Request our Business Associate Agreement, security overview, and applicable subprocessor information.