Skip to main content
Commure Scribe is built to protect patient data and meet the requirements of HIPAA-regulated environments. This page summarizes our core commitments; you can find more information in our Trust Center.

Certifications & attestations

  • SOC 2 Type II — independent attestation of our security controls.
  • HIPAA compliant — we operate as a Business Associate and sign BAAs with covered entities (see below).

Data protection

  • Encryption in transit: TLS 1.2 or higher.
  • Encryption at rest: AES-256.
  • Access controls: role-based access on a least-privilege model, with MFA and SSO support.
  • Hosting: US-based infrastructure; data is processed and stored in the United States.
  • Monitoring & testing: 24/7 intrusion detection, annual penetration testing, and automated vulnerability scanning.

Data retention

  • Patient demographic data, audio recordings, transcripts, and generated clinical outputs are retained for 6 years, consistent with healthcare recordkeeping and audit obligations.
  • You can access or delete your notes at any time during the retention period. When you delete a note, it is removed from your account view; a copy is preserved in encrypted storage, accessible only to authorized staff for audit purposes, until the retention period ends.

AI model training

  • PHI is never used to train AI models.

Subprocessors

  • We use vetted subprocessors that meet our security and compliance standards, are covered by Business Associate Agreements where they handle PHI, and undergo security and privacy reviews at least annually.

Business Associate Agreement (BAA)

  • A standard BAA is available for review, and we execute signed BAAs with customers.
  • To request or execute a BAA, contact our support team.

Breach notification

  • In the event of a breach, notification follows the process and timeline defined in your executed BAA, consistent with the HIPAA Breach Notification Rule.

For more detailed security information and reports, visit the Commure Trust Center.