Enterprise Security

Security & Compliance First.

Your patient data security and privacy are our absolute top priorities. We maintain the highest standards of healthcare compliance and enterprise-grade protection across every aspect of our platform.

HIPAA Compliant PHIPA Compliant BAA at signup
Our commitment

Our Commitment to HIPAA Compliance

HIPAA Compliant

At Myclinicalwriter.ai, we recognize the critical importance of safeguarding sensitive patient information in the world of healthcare. Compliance with the Health Insurance Portability and Accountability Act (HIPAA) isn't just a legal obligation for us—it's a commitment to uphold the trust you place in our application. With this core principle in mind, we've implemented the following measures to ensure your data is protected:

Data Encryption:

Every piece of data entered, stored, or transmitted is protected using state-of-the-art encryption methods, ensuring maximum security.

Stringent Access Controls:

We've set up robust controls to make sure that only authorized individuals can access specific patient data, protecting against unauthorized access and potential breaches.

Comprehensive Logging:

Every access or modification to patient records is meticulously logged. This level of detail ensures transparency and adheres to HIPAA's accountability standards.

Regular Audits:

Our system undergoes routine audits and vulnerability assessments, proactively identifying and mitigating potential security threats.

Dedicated Compliance Team:

Our team remains up-to-date with HIPAA regulations and amendments, ensuring our application remains compliant in an ever-evolving landscape.

Secure cloud storage

Azure-based infrastructure with enterprise-grade security: secure cloud storage with redundancy, end-to-end 256-bit encryption for all data, in transit and at rest.

With these measures in place, professionals can confidently utilize our application, trusting in our unwavering commitment to safeguarding sensitive patient data.

Security in Action

What happens to every record.

Scenario: A private practice handles sensitive patient information across multiple locations.

  1. Encrypt

    Encrypted everywhere

    All data encrypted in transit and at rest

  2. Restrict

    Role-based access

    Role-based access ensures only authorized staff can view records

  3. Record

    Automatic audit logs

    Automatic audit logs track all data access

  4. Review

    Ongoing assessment

    Regular security assessments and compliance monitoring

Outcome Practice maintains 100% HIPAA compliance while providing seamless access to authorized users.

Data Security and Privacy

Bank-level security infrastructure ensures patient data remains completely confidential and compliant with all healthcare regulations.

  • End-to-end 256-bit encryption
  • HIPAA and PHIPA compliant infrastructure
  • Secure cloud storage with redundancy
  • Audit trails and access controls
Security & Compliance

Enterprise protection, at a glance.

Full compliance with healthcare privacy regulations, and enterprise-grade protection built into every layer of the platform.

  • HIPAA Compliance Full healthcare privacy regulation adherence
  • Enterprise Security Bank-level security standards and protocols
  • End-to-End Encryption 256-bit encryption for all data
  • Audit Trails Complete access and modification logging
  • Role-Based Access Granular permission controls
  • Secure Cloud Storage Azure-based redundant infrastructure
HIPAA · PHIPA · BAA

Compliance you can read in full.

We don’t ask you to take our word for it. The agreement that governs how we handle protected health information is published, and you accept it when you create your account.

HIPAA compliant

Full compliance with US healthcare privacy regulations: the Health Insurance Portability and Accountability Act, as amended by the HITECH Act.

PHIPA compliant

For clinicians who work under Ontario’s Personal Health Information Protection Act, the platform is PHIPA compliant as well.

Business Associate Agreement

Every account agrees to our BAA at registration, alongside the Terms of Use. You can read the whole agreement before you sign up.

Read the BAA

From the BAA, word for word

  • § 2.2Implement encryption and decryption mechanisms for ePHI.
  • § 2.3Notify CE without unreasonable delay and in no case later than sixty (60) days after discovery of a Breach of Unsecured PHI
  • § 3.2BA agrees to make uses and disclosures and requests for PHI consistent with CE’s minimum necessary policies and procedures.
  • § 5.3Upon termination, BA shall return or destroy all PHI received from CE, or created or received by BA on behalf of CE.

BA is My Clinical Writer; CE is you, the covered entity. Read the full agreement or the Terms of Use.

Privacy by design

Your old records stay on your computer.

Records Vault turns an exported EHR folder into a searchable archive on your own computer. Drag in PDFs, Word docs and spreadsheets, search by keyword or meaning, and add more records anytime.

Nothing is ever uploaded.

This computer
Your part

Security is a shared job.

As our Terms of Use say plainly, no method of transmission over the Internet or electronic storage is 100% secure. A few habits on your side close the gap.

Guard your account

You’re responsible for safeguarding your password. Tell us right away about any unauthorized access to your account.

Keep PHI out of email

Patient information belongs inside the app. Don’t include it in the contact form or in emails to our team.

Review every draft

AI-generated documentation must be reviewed and verified by you before use. The tool never replaces professional judgment.

Security FAQ

Questions, answered.

Is My Clinical Writer HIPAA compliant?

Yes, My Clinical Writer is fully HIPAA compliant. We implement administrative, physical, and technical safeguards to protect patient health information (PHI) in accordance with HIPAA regulations.

My Clinical Writer is HIPAA and PHIPA compliant. Data is encrypted in transit and at rest, access is limited to authorized individuals, every access or modification to patient records is logged, the system undergoes routine audits and vulnerability assessments, and a dedicated compliance team keeps up with HIPAA regulations and amendments.

Do you sign a Business Associate Agreement?

Yes. Every account agrees to our Business Associate Agreement when registering, together with the Terms of Use. You can read the full BAA before you sign up.

Is my data secure?

Yes, we’re fully HIPAA compliant with end-to-end encryption and enterprise-grade security measures to protect your sensitive data. All plans include HIPAA compliance and secure data handling.

How is patient data encrypted?

All patient data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. We use enterprise-grade encryption protocols to ensure maximum security.

Where is patient data stored?

Patient data is stored in HIPAA-compliant data centers with enterprise-grade security, featuring redundant backups and 24/7 security monitoring.

That means secure cloud storage on Azure-based infrastructure, encrypted at rest. Records Vault is the exception by design: its archive stays on your own computer.

Does Records Vault upload my old EHR records?

No. Records Vault turns an exported EHR folder into a searchable archive on your own computer. Nothing is ever uploaded.

Who owns the content I create?

You do. Under our Terms of Use you retain ownership of any content you submit. We only use, store and process it to provide the service to you.

What happens to PHI if I stop using the service?

Under section 5.3 of the BAA, when the agreement ends we return or destroy all PHI we received from you or created on your behalf, including any held by subcontractors. If that isn’t feasible, we tell you why and the agreement’s protections continue to apply to that information.

Does the AI replace my clinical judgment?

No. My Clinical Writer is a tool to assist with documentation and does not replace professional medical judgment or clinical decision-making. All generated documentation must be reviewed and verified by you before use.

Still have a question? Email support@myclinicalwriter.com or contact us. Please leave patient information out of your message. Want to know who is behind the platform? Meet our founders.

Get started

Document with confidence.

All plans include HIPAA compliance and secure data handling. Start with a free trial, no credit card required.

Compare plans: Pricing · All plan details