Clinical data handled the way clinical data should be.
Prioriq is built with HIPAA controls throughout — from the infrastructure layer through the application layer. We are not yet SOC 2 Type II certified; our audit readiness program is underway with a Q4 2026 target. What we can tell you now: end-to-end encryption, PHI never used for model training, audio discarded post-transcription, and BAA available on request.
Six pillars. Every account.
These controls apply to every Prioriq account — Clinic, Practice, and System plans. PHI security is not a premium feature.
All clinical data is encrypted in transit (TLS 1.3) and at rest (AES-256). Encryption keys are managed per-account with AWS KMS. No raw PHI is transmitted unencrypted at any layer.
Prioriq is built with HIPAA controls in mind — access controls, audit logging, breach notification procedures, and workforce training on PHI handling. We maintain documentation of our HIPAA compliance program and make it available to customers upon request.
Provider, staff, admin, and read-only roles with fine-grained data access policies. No user can access patient records outside their own assigned encounters. Session tokens expire on idle after 30 minutes.
We are currently undergoing our SOC 2 Type II readiness assessment, targeting completion in Q4 2026. The control framework is already in place — audit evidence collection has begun. We will share the report with customers when available.
Prioriq runs entirely on AWS HIPAA-eligible services: EC2, RDS (encrypted), S3 (server-side encryption), CloudTrail (audit logging), and CloudWatch. All services are deployed in US-East-1 with cross-region backup in US-West-2.
Every access to PHI-containing resources is logged with timestamp, user identity, resource identifier, and action type. Logs are immutable, stored for 7 years, and available to customers for compliance reviews on the System plan.
Where your PHI goes — and where it doesn't.
Audio is never stored
Ambient encounter audio is processed in real time for transcription and then immediately discarded. No audio recording is retained after transcription completes. The patient encounter audio does not leave the Prioriq processing environment in any persistent form.
PHI is never used for model training
PHI processed by Prioriq is never used to train or fine-tune NLP models. Our clinical documentation models are trained on de-identified and synthetic clinical datasets — not on production encounter data from customers. This is a written commitment, not just a policy summary, and it is included in our BAA language. Your patients' data does not improve anyone else's product.
Business Associate Agreement (BAA)
A signed Business Associate Agreement (BAA) is required before Prioriq processes any PHI — without exception. The BAA is included as a standard exhibit in all System plan contracts and available on the Practice plan upon request. Clinic plan customers who require a BAA should contact us; we accommodate all BAA requests regardless of plan tier. The BAA template is available for legal review before any contract discussion begins.
Request a BAANeed to review security documentation?
We will provide our security questionnaire responses (SIG Lite or your own format), data processing addendum, HIPAA compliance program summary, and BAA template before any contract discussion. Contact us and specify what your security review requires.
Request security docs