> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scribe.commure.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Compliance

> How Commure Scribe protects patient data and meets HIPAA requirements — certifications, encryption, data retention, subprocessors, and BAAs.

Commure Scribe is built to protect patient data and meet the requirements of HIPAA-regulated environments. This page summarizes our core commitments; you can find more information in our [Trust Center](https://www.commure.com/trust-center).

## Certifications & attestations

* **SOC 2 Type II** — independent attestation of our security controls.
* **HIPAA compliant** — we operate as a Business Associate and sign BAAs with covered entities (see below).

## Data protection

* **Encryption in transit:** TLS 1.2 or higher.
* **Encryption at rest:** AES-256.
* **Access controls:** role-based access on a least-privilege model, with MFA and SSO support.
* **Hosting:** US-based infrastructure; data is processed and stored in the United States.
* **Monitoring & testing:** 24/7 intrusion detection, annual penetration testing, and automated vulnerability scanning.

## Data retention

* Patient demographic data, audio recordings, transcripts, and generated clinical outputs are retained for **6 years**, consistent with healthcare recordkeeping and audit obligations.
* You can access or delete your notes at any time during the retention period. When you delete a note, it is removed from your account view; a copy is preserved in encrypted storage, accessible only to authorized staff for audit purposes, until the retention period ends.

## AI model training

* PHI is **never** used to train AI models.

## Subprocessors

* We use vetted subprocessors that meet our security and compliance standards, are covered by Business Associate Agreements where they handle PHI, and undergo security and privacy reviews at least annually.

## Business Associate Agreement (BAA)

* A standard BAA is available for review, and we execute signed BAAs with customers.
* To request or execute a BAA, contact our support team.

## Breach notification

* In the event of a breach, notification follows the process and timeline defined in your executed BAA, consistent with the HIPAA Breach Notification Rule.

***

For more detailed security information and reports, visit the [Commure Trust Center](https://www.commure.com/trust-center).
