Security & compliance posture for healthcare workflows.
Security, auditability, and interoperability are part of the architecture — designed for clinical environments where trust and accountability matter.
Architecture overview
Secure sign-in and access
Each clinician and staff member uses their own protected account. Access is limited to what their role requires, so people see only the information and tools appropriate to their work in a multi-clinician practice.
Encryption
TLS enforced for data in transit. AES-256 encryption via AWS KMS for data at rest. Key management follows AWS best practices for healthcare workloads.
Auditability
Audit logging and traceability for clinical and operational workflows. Designed to support accountability, incident response, and compliance readiness.
Interoperability-aware foundation
FHIR R4 resources, SMART on FHIR authorization, C-CDA export and ingest, and HL7 v2 ADT processing are part of the product's technical direction for standards-based data exchange.
Clinician-in-the-loop AI
AI-generated documentation is always a draft. Clinicians review, correct, and finalize every note. No autonomous clinical decisions are made by the system.
Responsible AI
- Scribe Mutual is clinical documentation assistance software. It is not intended to diagnose, treat, cure, or prevent disease.
- AI-generated content is intended to be reviewed, corrected, and finalized by a licensed clinician before use in the medical record.
- Scribe Mutual does not make autonomous clinical decisions. Clinicians remain responsible for the accuracy and completeness of all documentation.
What Scribe Mutual does not claim
Transparency matters. Scribe Mutual does not claim:
- HIPAA certification (HIPAA does not have a certification program)
- ONC certification (certification process is in progress but not complete)
- SOC 2 certification
- HITRUST certification
- FDA approval or clearance
- Guaranteed accuracy of AI-generated content
- Flawless model output without clinician review or verification
- Guaranteed clinical outcomes
Reporting a security issue
We welcome reports from security researchers and users who believe they’ve found a vulnerability in Scribe Mutual. Coordinated disclosure helps us protect patients and clinicians.
How to report
Email shuo.li@scribemutual.com with the subject line “Security — [short description].” Please include what you found, the steps to reproduce it, the affected app area or URL, and the potential impact (a proof of concept helps). This inbox is monitored, and we aim to acknowledge your report within three business days.
Scope
The Scribe Mutual application and the scribemutual.com website.
Please do
- Report promptly after discovery.
- Give us a reasonable opportunity to investigate and fix before disclosing publicly.
- Use only your own test accounts and synthetic data.
Please don’t
- Access, modify, or delete data that isn’t yours.
- Degrade or disrupt the service (no denial-of-service or automated scanning that affects availability).
- Attempt social engineering, phishing, or physical attacks against our staff or facilities.
- Because Scribe Mutual handles protected health information, never include real patient data (PHI) in a report. If you believe you’ve encountered PHI, stop, do not download or retain it, and tell us immediately.
Safe harbor
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we consider activity consistent with this policy to be authorized. We’ll work with you to understand and resolve the issue quickly.
Our commitment
We’ll acknowledge your report, keep you updated as we investigate, remediate valid issues as quickly as we reasonably can, and credit you once resolved if you’d like. We ask that you coordinate the timing of any public disclosure with us.
Learn more about Scribe Mutual
If you have questions about our security approach or would like to discuss your practice's documentation needs, request a conversation.