Security & Compliance

Clinical data handled the way clinical data should be.

Prioriq is built with HIPAA controls throughout — from the infrastructure layer through the application layer. We are not yet SOC 2 Type II certified; our audit readiness program is underway with a Q4 2026 target. What we can tell you now: end-to-end encryption, PHI never used for model training, audio discarded post-transcription, and BAA available on request.

Abstract concept of encrypted clinical data security and access control

Six pillars. Every account.

These controls apply to every Prioriq account — Clinic, Practice, and System plans. PHI security is not a premium feature.

End-to-end encryption

All clinical data is encrypted in transit (TLS 1.3) and at rest (AES-256). Encryption keys are managed per-account with AWS KMS. No raw PHI is transmitted unencrypted at any layer.

HIPAA-oriented controls

Prioriq is built with HIPAA controls in mind — access controls, audit logging, breach notification procedures, and workforce training on PHI handling. We maintain documentation of our HIPAA compliance program and make it available to customers upon request.

Role-based access control

Provider, staff, admin, and read-only roles with fine-grained data access policies. No user can access patient records outside their own assigned encounters. Session tokens expire on idle after 30 minutes.

SOC 2 controls in progress

We are currently undergoing our SOC 2 Type II readiness assessment, targeting completion in Q4 2026. The control framework is already in place — audit evidence collection has begun. We will share the report with customers when available.

AWS HIPAA-eligible infrastructure

Prioriq runs entirely on AWS HIPAA-eligible services: EC2, RDS (encrypted), S3 (server-side encryption), CloudTrail (audit logging), and CloudWatch. All services are deployed in US-East-1 with cross-region backup in US-West-2.

Audit logging

Every access to PHI-containing resources is logged with timestamp, user identity, resource identifier, and action type. Logs are immutable, stored for 7 years, and available to customers for compliance reviews on the System plan.

Where your PHI goes — and where it doesn't.

Audio is never stored

Ambient encounter audio is processed in real time for transcription and then immediately discarded. No audio recording is retained after transcription completes. The patient encounter audio does not leave the Prioriq processing environment in any persistent form.

Data Flow — Audio
Capture → NLP processing
Audio discarded post-transcription
Structured note retained in EHR

PHI is never used for model training

PHI processed by Prioriq is never used to train or fine-tune NLP models. Our clinical documentation models are trained on de-identified and synthetic clinical datasets — not on production encounter data from customers. This is a written commitment, not just a policy summary, and it is included in our BAA language. Your patients' data does not improve anyone else's product.

Data Use Policy
PHI used for care delivery only
No PHI in model training pipelines
No data sold to third parties
Data deletion on contract end

Business Associate Agreement (BAA)

A signed Business Associate Agreement (BAA) is required before Prioriq processes any PHI — without exception. The BAA is included as a standard exhibit in all System plan contracts and available on the Practice plan upon request. Clinic plan customers who require a BAA should contact us; we accommodate all BAA requests regardless of plan tier. The BAA template is available for legal review before any contract discussion begins.

Request a BAA

Need to review security documentation?

We will provide our security questionnaire responses (SIG Lite or your own format), data processing addendum, HIPAA compliance program summary, and BAA template before any contract discussion. Contact us and specify what your security review requires.

Request security docs