Security & compliance posture for healthcare workflows.

Security, auditability, and interoperability are part of the architecture — designed for clinical environments where trust and accountability matter.

Architecture overview

Secure sign-in and access

Each clinician and staff member uses their own protected account. Access is limited to what their role requires, so people see only the information and tools appropriate to their work in a multi-clinician practice.

Encryption

TLS enforced for data in transit. AES-256 encryption via AWS KMS for data at rest. Key management follows AWS best practices for healthcare workloads.

Auditability

Audit logging and traceability for clinical and operational workflows. Designed to support accountability, incident response, and compliance readiness.

Interoperability-aware foundation

FHIR R4 resources, SMART on FHIR authorization, C-CDA export and ingest, and HL7 v2 ADT processing are part of the product's technical direction for standards-based data exchange.

Clinician-in-the-loop AI

AI-generated documentation is always a draft. Clinicians review, correct, and finalize every note. No autonomous clinical decisions are made by the system.

Responsible AI

  • Scribe Mutual is clinical documentation assistance software. It is not intended to diagnose, treat, cure, or prevent disease.
  • AI-generated content is intended to be reviewed, corrected, and finalized by a licensed clinician before use in the medical record.
  • Scribe Mutual does not make autonomous clinical decisions. Clinicians remain responsible for the accuracy and completeness of all documentation.

What Scribe Mutual does not claim

Transparency matters. Scribe Mutual does not claim:

  • HIPAA certification (HIPAA does not have a certification program)
  • ONC certification (certification process is in progress but not complete)
  • SOC 2 certification
  • HITRUST certification
  • FDA approval or clearance
  • Guaranteed accuracy of AI-generated content
  • Flawless model output without clinician review or verification
  • Guaranteed clinical outcomes

Reporting a security issue

We welcome reports from security researchers and users who believe they’ve found a vulnerability in Scribe Mutual. Coordinated disclosure helps us protect patients and clinicians.

How to report

Email shuo.li@scribemutual.com with the subject line “Security — [short description].” Please include what you found, the steps to reproduce it, the affected app area or URL, and the potential impact (a proof of concept helps). This inbox is monitored, and we aim to acknowledge your report within three business days.

Scope

The Scribe Mutual application and the scribemutual.com website.

Please do

  • Report promptly after discovery.
  • Give us a reasonable opportunity to investigate and fix before disclosing publicly.
  • Use only your own test accounts and synthetic data.

Please don’t

  • Access, modify, or delete data that isn’t yours.
  • Degrade or disrupt the service (no denial-of-service or automated scanning that affects availability).
  • Attempt social engineering, phishing, or physical attacks against our staff or facilities.
  • Because Scribe Mutual handles protected health information, never include real patient data (PHI) in a report. If you believe you’ve encountered PHI, stop, do not download or retain it, and tell us immediately.

Safe harbor

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we consider activity consistent with this policy to be authorized. We’ll work with you to understand and resolve the issue quickly.

Our commitment

We’ll acknowledge your report, keep you updated as we investigate, remediate valid issues as quickly as we reasonably can, and credit you once resolved if you’d like. We ask that you coordinate the timing of any public disclosure with us.

A machine-readable contact is published at /.well-known/security.txt.

Learn more about Scribe Mutual

If you have questions about our security approach or would like to discuss your practice's documentation needs, request a conversation.