Try for Free
Angle Icon
Note Bloat

How Freed Handles Data, Privacy, & Compliance

Author Image
Published in
 
From the Freedos
  • 
4
 Min Read
  • 
Jul 14, 2025
Subscribe
Alert IconAlert Icon
Reviewed by
 
Lauren Funaro
From the Freedos
July 14, 2025

How Freed Handles Data, Privacy, & Compliance

A clear look at our security-first AI scribe — built for HIPAA compliance, clinician control, and peace of mind

Reviewed By
From the Freedos
Published Date
July 14, 2025
Time to read
4
min.

Arrow Icon
Arrow Icon
Arrow Icon
Arrow Icon

Arrow Icon
Arrow Icon
Arrow Icon
Arrow Icon

Doctor or Nurse Speech Bubble Icon

Table of Contents

Your first questions are usually the most important: "Is this tool secure? Will it protect my patients' data? Are we covered from a compliance standpoint?" 

These are fundamental to running a responsible healthcare practice. And with AI, the stakes feel even higher.

That’s why Freed’s AI scribe was built for clinicians, with your healthcare privacy and compliance requirements at the forefront. 

Here’s what our security-first approach means for your practice. 

Where does your data go? 

All patient information that flows through Freed is protected with multiple layers of security:

  • Encrypted end-to-end: All data is encrypted in transit (TLS 1.2–1.3) and at rest (AES-256). This means your patient conversations are protected whether they're being processed or stored.
  • No audio retention: Freed does not retain audio by default. We process the audio, generate your note, then automatically delete the recording. Optional retention settings are available for notes per user or organization.
  • Secure infrastructure: All processing occurs in secure, HIPAA-compliant environments. We only use third parties with signed BAAs and "no less restrictive" protections.

Who owns and controls the data? 

You and your clinicians. Each user gets their own secure workspace, with full ownership of their data. And you can delete or export data at any time — before or after the contract ends.

When it comes to AI training, Freed does not use identifiable data to train its models. We follow strict de-identification and privacy protocols, and never share your clinic's data externally.

Learn more about how Freed’s AI works behind the scenes.

"I have full confidence. I have no worry about any audits whatsoever. I'm like, bring it because I know that the way they have gotten stuff laid out, it's done... no concern about an audit. It has everything." — Mariah H, Psychiatric NP
Read Mariah’s story

Patient consent

Freed encourages (and some jurisdictions may require) obtaining consent before starting the recording. Obtaining consent remains the responsibility of the clinic, in line with your policies.

Not required by Freed: Consent practices are up to each organization, and we consider it to be best practice. But, Freed doesn’t require it. 

Common options clinics use for patient consent:

  • Verbal consent at the start of each visit (here’s a script you can follow)
  • Clinic signage (e.g., "This visit may be documented using ambient scribe technology")
  • Patient consent during intake

HIPAA compliance (and other standards) 

Freed meets or exceeds all requirements under:

  • HIPAA
  • HITECH
  • SOC Type 1 and Type 2

Our Business Associate Agreement (BAA) is in use with hundreds of health systems and rarely requires edits.

We also enforce Open Worldwide Application Security Project (OWASP) secure coding standards with regular audits. All data is stored within the United States.

Additionally, Freed’s infrastructure includes protections validated via third-party security assessments and contracts. 

Learn more about our security and compliance protocols

Legal details

Beyond security and compliance, practices want to understand the legal framework around using Freed. Our terms are designed to be fair and straightforward:

  • Mutual indemnification: You're covered if we cause legal issues (e.g., IP infringement); we're covered if Freed is misused or used without consent.
  • Standard liability cap: Set at 12 months of fees paid, with carveouts for gross negligence or breaches of confidentiality.
  • Termination and offboarding: We honor 30-day notice terms and support full data export or deletion upon request.

Ready to see for yourself?

You shouldn’t have to choose between staying secure and staying above water. With Freed, you get both — robust protection and simple, stress-free compliance.

You don't have to commit your whole practice to see what secure, compliant AI documentation can do. Many practices start with a pilot of one or two clinicians. The rest of the team joins once they've seen the impact. 

Ready to lighten the load while keeping your practice secure? Join the thousands of clinicians who are simplifying charting with Freed.

Start a free trial or connect with our team to learn more about how Freed protects your practice.



Learn more about our compliance and security measures in the Freed Help Center.

FAQs

Frequently asked questions from clinicians and medical practitioners.

Question Icon

Is Freed secure and compliant with healthcare rules and regulations?

Angle Icon
Question Icon

How much does Freed cost?

Angle Icon
Question Icon

How can I get started with Freed?

Angle Icon
Author Image
Published in
 
From the Freedos
  • 
4
 Min Read
  • 
Jul 14, 2025
Subscribe
Alert IconAlert Icon
Reviewed by
 
Lauren Funaro