Trust at ToothNote.ai

Built for protected health information.

ToothNote.ai signs a Business Associate Agreement with customer practices and uses administrative, technical, and contractual safeguards to protect patient information. Clinicians review and approve every clinical document before it is used or delivered.

Safeguards

Security across the service.

These are the public facts a practice needs before beginning a deeper review.

Encrypted in transit and at rest

Patient information is encrypted during transmission and while stored, including applicable backups.

Controlled access

Passwordless authentication and role-based access controls help ensure users can reach only the information appropriate to their practice and role.

Established cloud platform

Hosted on a SOC 2 Type II audited cloud platform eligible for HIPAA workloads. That audit applies to the hosting platform, not to ToothNote.ai as a company.

Audit logging

Relevant account and clinical-document activity is recorded to support security, operational, and compliance review.

Backups and recovery

Encrypted backups and documented recovery procedures support service continuity.

Customer and subprocessor BAAs

ToothNote.ai provides a Business Associate Agreement to customer practices and maintains appropriate agreements with subprocessors that handle PHI.

AI and your data

Clinical AI with clear boundaries.

No shared-model training

Customer PHI is not used to train shared foundation models.

Clinician review

AI-generated clinical content remains a draft until a clinician reviews and approves it.

Contractual safeguards

Providers that process PHI for ToothNote.ai are governed as subprocessors under appropriate contractual and security requirements.

Common questions

What evaluators ask us first.

Is ToothNote.ai HIPAA compliant?

Yes. ToothNote.ai is HIPAA compliant.

Will ToothNote.ai sign a Business Associate Agreement with our practice?

Yes. ToothNote.ai provides a Business Associate Agreement to customer practices and maintains appropriate agreements with subprocessors that handle PHI. Email hello@toothnote.ai to request it along with the security overview and applicable subprocessor information.

Is our patient data used to train AI models?

No. Customer PHI is not used to train shared foundation models.

Does ToothNote.ai have SOC 2?

ToothNote.ai is hosted on a SOC 2 Type II audited cloud platform eligible for HIPAA workloads. That audit applies to the hosting platform, not to ToothNote.ai as a company. We state the distinction plainly rather than implying a company-level certification we do not hold.

Who inside our practice can see a given patient's information?

Access is controlled by role. Passwordless authentication and role-based access controls help ensure users can reach only the information appropriate to their practice and role.

Security review

Evaluating ToothNote.ai?

Request our Business Associate Agreement, security overview, and applicable subprocessor information.

Contact us