When you're evaluating AI scribes for your practice, security and compliance are some of the most important questions you can ask. Patient data protection is nonnegotiable.
This FAQ covers everything you need to know about HIPAA compliance, data security, patient privacy, and the technical details that matter most to healthcare organizations.
HIPAA compliance for AI scribes means the technology meets all standards set by the Health Insurance Portability and Accountability Act for protecting patient health information (PHI). This includes:
For an AI scribe like Freed, HIPAA compliance also means the AI models don't train on identifiable patient data, recordings are handled securely and deleted after note generation, and every system component follows strict privacy and security protocols. Security is built into every layer of the technology.
At a minimum, an AI scribe should support:
Before using an AI scribe, providers should verify:
Compliance theater refers to organizations that create the appearance of security and compliance without implementing meaningful protections. This includes vendors who:
To avoid compliance theater, verify these specifics:
What to verify:
Yes. Any AI scribe that records, transcribes, or processes encounters on behalf of a covered entity is acting as a business associate. That triggers the need for a BAA, a security risk analysis, and ongoing oversight of the vendor’s safeguards.
Ambient or AI scribes like Freed that only assist with documentation and do not diagnose, treat, or make clinical decisions have generally not been treated as FDA-regulated medical devices. The clinician remains responsible for reviewing and signing the note, and Freed functions as a documentation support tool rather than a diagnostic system.
Freed is not FDA-approved, because it isn’t intended to diagnose or treat patients or replace clinical judgment. It supports documentation; it doesn’t make medical decisions.
You can disclose AI use by explaining that Freed is a secure, HIPAA-compliant tool that helps with documentation while you focus on patient care. It's important to be transparent about how technology supports your work.
Here's what patients should know:
Many clinicians find that when they explain AI scribing this way, patients appreciate the increased attention and engagement during appointments.
To convince your clinic or employer to allow AI scribes, focus on three key areas: time savings, cost reduction, and compliance.
Time savings: AI scribes help providers cut documentation time, reducing burnout and freeing hours for more patients or personal time.
Cost reduction: AI scribes are often more affordable than human scribes, with no hiring, training, or turnover costs.
Compliance: Freed in particular is HIPAA-compliant, HITECH-aligned, and SOC 2 Type 2 certified, with encryption in transit and at rest and no long-term storage of audio recordings. It’s designed to slot into your existing EHR workflow without requiring major changes.
Proven results: Share pilot data or start a free trial to demonstrate real workflow improvements, accuracy, and measurable ROI.
Yes, Freed is HIPAA-compliant and HITECH-aligned. All data is encrypted both in transit and at rest, and access is strictly controlled to authorized users only. Freed follows HIPAA security and privacy standards to protect patient information and maintains Business Associate Agreements (BAAs) with all enterprise customers. This ensures your clinical data and patient notes are handled with the highest level of confidentiality and compliance.
Freed's systems exceed HIPAA and HITECH requirements and are SOC 2 Type 2 certified. Our cryptographic modules follow FIPS PUB 140-2 standards. In addition, all of Freed’s stored data is stored within the United States.
💡Learn more about how Freed maintains HIPAA compliance and security.
Freed holds several industry-leading security certifications and compliance standards:
Freed’s ongoing commitment to security takes place through regular third-party reviews, vulnerability scanning via Azure Security Center and Drata, and continuous monitoring.
All patient data is stored securely in Microsoft Azure's encrypted cloud storage, exclusively within the United States. Freed has a HIPAA-compliant Business Associate Agreement with Microsoft and leverages Azure's high-availability infrastructure to ensure data is always accessible while remaining secure.
Protected Health Information is encrypted at rest using AES-256 encryption and encrypted in transit using TLS 1.2-1.3. This means your data is protected whether it's being stored, processed, or transferred between systems.
Freed is built on industry best practices with multiple layers of privacy protection:
Patient recordings are temporarily saved in a secure and HIPAA-compliant manner only until note summaries and quality checks are complete. Once the note is successfully generated, the audio recording is automatically deleted. Freed does not retain audio by default.
This approach minimizes PHI retention and exposure while still ensuring high-quality documentation. Clinicians never have to worry about old recordings sitting in the system.
Audio recordings are not stored and are immediately deleted upon successful note generation, which happens within 60 seconds of the encounter ending. Users can manually delete notes at any time or enable a 30-day retention policy to ensure their notes are deleted from Freed's system on a routine basis.
This gives you complete control over how long clinical documentation remains in Freed while maintaining the security and compliance standards your practice requires.
You can find more specifics in Freed’s Security Center.
Freed uses industry-standard encryption protocols at multiple levels:
These multiple layers of encryption ensure that patient data is protected at every stage—from capture through storage to final deletion.
You do. Clinicians retain full ownership of their data. Users can delete or export data at any time—before or after the contract ends.
When it comes to AI training, Freed does not use identifiable data to train its models. We follow strict de-identification and privacy protocols, and we never share your clinic's data externally. Your practice's information stays yours.
No. Freed does not use Protected Health Information for AI training purposes. Our AI model is designed with HIPAA compliance at its core and is only trained on de-identified notes that have been stripped of all patient identifiers.
This means every conversation you have with patients is private. Our models are only trained on de-identified notes, and we don’t share your clinic’s data with external parties.
Freed is not FDA-approved, and it doesn't need to be. The FDA regulates software that functions as a medical device—tools that diagnose, treat, or directly affect patient health decisions.
Freed, on the other hand, is a clinical documentation platform that assists providers by transcribing and structuring notes from medical conversations. It doesn't make diagnostic suggestions, treatment recommendations, or clinical decisions. It falls outside the FDA's regulatory scope because it's a documentation tool, not a medical decision-making device.
Freed maintains HIPAA compliance through comprehensive security measures across multiple domains:
Internal personnel security:
Compliance framework:
Secure development:
Cloud infrastructure:
Network security:
Monitoring and response:
Freed's legal framework is designed to be fair and straightforward:
Mutual indemnification: You're covered if we cause legal issues (e.g., IP infringement); we're covered if Freed is misused or used without consent.
Standard liability cap: Set at 12 months of fees paid, with carveouts for gross negligence or breaches of confidentiality.
Termination and offboarding: We honor 30-day notice terms and support full data export or deletion upon request.
Business Associate Agreement: Our BAA is in use with hundreds of health systems and rarely requires edits. It covers your entire organization, ensuring HIPAA compliance for all users.
These terms protect both parties while ensuring you have the flexibility and control you need over your practice's data.
Yes. Freed provides robust access management capabilities:
For organizations, admins can centrally manage users, track adoption, and manage group settings such as SSO or MFA through built-in dashboards.
Yes, Freed provides detailed reporting for group admins to track usage, including visits, minutes, and provider activity. You can easily export this data for integration with your BI or analytics tools.
Reports can be downloaded in common formats like CSV, allowing you to combine Freed data with other business metrics for deeper insights into platform adoption, productivity, and documentation efficiency across your organization.
This transparency helps you measure ROI, track compliance, and identify opportunities for improving documentation workflows.
Freed offers admin reporting dashboards that make it easy to track adoption and usage across providers. You can monitor key metrics such as total visits, minutes recorded, and active users over time.
Data can be filtered by provider or department to identify engagement trends and partnership opportunities. For deeper analysis, reports can also be exported to CSV or integrated with your organization's BI tools to measure ongoing adoption and impact.
Each organization is also assigned a dedicated group account manager who partners with you to review adoption trends, share insights, and support rollout or engagement efforts.
Freed maintains strict vendor management protocols:
This ensures that even when working with third-party services, patient data remains protected to the same high standards throughout the entire technology stack.
Freed maintains comprehensive security monitoring and incident response capabilities:
24/7 monitoring:
Incident response:
Security audits:
Proactive security:
This multi-layered approach ensures that potential security issues are identified and addressed quickly, minimizing any risk to your practice.
Freed stands out in several ways:
Comprehensive certification: Freed is HIPAA-compliant, HITECH-aligned, and SOC 2 Type 2 certified, with cryptographic modules that follow FIPS PUB 140-2 standards.
No audio retention by default: Patient recordings are saved only until the note is completed and quality checks are done, then automatically deleted. There’s no long-term audio storage by default.
No training on PHI: Freed’s AI is only trained on de-identified notes. Protected health information is never used for AI training, helping protect patient privacy.
Storage in the U.S.: All data is processed and stored in U.S.-based Microsoft Azure data centers under a HIPAA-compliant BAA.
Transparent practices: Freed publishes clear documentation on security, data handling, and legal terms so IT and compliance teams can review details up front.
Proven track record: In use by hundreds of health systems and thousands of clinicians who have thoroughly vetted security practices.
Dedicated support: Each organization gets a dedicated account manager who understands your specific security requirements.
We're happy to connect your team with a Freed specialist—whether it's sales, legal, or technical. Security and compliance are too important to leave unanswered.
Contact us:
For organizations considering Freed, we can arrange calls with our security team, provide detailed documentation for your IT and compliance reviewers, and answer any technical questions your team has.
Your trust is our highest priority, and we're committed to providing complete transparency about how we protect patient data and maintain compliance.
You shouldn't have to choose between staying secure and staying above water. With Freed, you get both.
Join the thousands of clinicians who are simplifying charting with Freed.
Start a free trial to learn more about how Freed protects your practice.
When you're evaluating AI scribes for your practice, security and compliance are some of the most important questions you can ask. Patient data protection is nonnegotiable.
This FAQ covers everything you need to know about HIPAA compliance, data security, patient privacy, and the technical details that matter most to healthcare organizations.
HIPAA compliance for AI scribes means the technology meets all standards set by the Health Insurance Portability and Accountability Act for protecting patient health information (PHI). This includes:
For an AI scribe like Freed, HIPAA compliance also means the AI models don't train on identifiable patient data, recordings are handled securely and deleted after note generation, and every system component follows strict privacy and security protocols. Security is built into every layer of the technology.
At a minimum, an AI scribe should support:
Before using an AI scribe, providers should verify:
Compliance theater refers to organizations that create the appearance of security and compliance without implementing meaningful protections. This includes vendors who:
To avoid compliance theater, verify these specifics:
What to verify:
Yes. Any AI scribe that records, transcribes, or processes encounters on behalf of a covered entity is acting as a business associate. That triggers the need for a BAA, a security risk analysis, and ongoing oversight of the vendor’s safeguards.
Ambient or AI scribes like Freed that only assist with documentation and do not diagnose, treat, or make clinical decisions have generally not been treated as FDA-regulated medical devices. The clinician remains responsible for reviewing and signing the note, and Freed functions as a documentation support tool rather than a diagnostic system.
Freed is not FDA-approved, because it isn’t intended to diagnose or treat patients or replace clinical judgment. It supports documentation; it doesn’t make medical decisions.
You can disclose AI use by explaining that Freed is a secure, HIPAA-compliant tool that helps with documentation while you focus on patient care. It's important to be transparent about how technology supports your work.
Here's what patients should know:
Many clinicians find that when they explain AI scribing this way, patients appreciate the increased attention and engagement during appointments.
To convince your clinic or employer to allow AI scribes, focus on three key areas: time savings, cost reduction, and compliance.
Time savings: AI scribes help providers cut documentation time, reducing burnout and freeing hours for more patients or personal time.
Cost reduction: AI scribes are often more affordable than human scribes, with no hiring, training, or turnover costs.
Compliance: Freed in particular is HIPAA-compliant, HITECH-aligned, and SOC 2 Type 2 certified, with encryption in transit and at rest and no long-term storage of audio recordings. It’s designed to slot into your existing EHR workflow without requiring major changes.
Proven results: Share pilot data or start a free trial to demonstrate real workflow improvements, accuracy, and measurable ROI.
Yes, Freed is HIPAA-compliant and HITECH-aligned. All data is encrypted both in transit and at rest, and access is strictly controlled to authorized users only. Freed follows HIPAA security and privacy standards to protect patient information and maintains Business Associate Agreements (BAAs) with all enterprise customers. This ensures your clinical data and patient notes are handled with the highest level of confidentiality and compliance.
Freed's systems exceed HIPAA and HITECH requirements and are SOC 2 Type 2 certified. Our cryptographic modules follow FIPS PUB 140-2 standards. In addition, all of Freed’s stored data is stored within the United States.
💡Learn more about how Freed maintains HIPAA compliance and security.
Freed holds several industry-leading security certifications and compliance standards:
Freed’s ongoing commitment to security takes place through regular third-party reviews, vulnerability scanning via Azure Security Center and Drata, and continuous monitoring.
All patient data is stored securely in Microsoft Azure's encrypted cloud storage, exclusively within the United States. Freed has a HIPAA-compliant Business Associate Agreement with Microsoft and leverages Azure's high-availability infrastructure to ensure data is always accessible while remaining secure.
Protected Health Information is encrypted at rest using AES-256 encryption and encrypted in transit using TLS 1.2-1.3. This means your data is protected whether it's being stored, processed, or transferred between systems.
Freed is built on industry best practices with multiple layers of privacy protection:
Patient recordings are temporarily saved in a secure and HIPAA-compliant manner only until note summaries and quality checks are complete. Once the note is successfully generated, the audio recording is automatically deleted. Freed does not retain audio by default.
This approach minimizes PHI retention and exposure while still ensuring high-quality documentation. Clinicians never have to worry about old recordings sitting in the system.
Audio recordings are not stored and are immediately deleted upon successful note generation, which happens within 60 seconds of the encounter ending. Users can manually delete notes at any time or enable a 30-day retention policy to ensure their notes are deleted from Freed's system on a routine basis.
This gives you complete control over how long clinical documentation remains in Freed while maintaining the security and compliance standards your practice requires.
You can find more specifics in Freed’s Security Center.
Freed uses industry-standard encryption protocols at multiple levels:
These multiple layers of encryption ensure that patient data is protected at every stage—from capture through storage to final deletion.
You do. Clinicians retain full ownership of their data. Users can delete or export data at any time—before or after the contract ends.
When it comes to AI training, Freed does not use identifiable data to train its models. We follow strict de-identification and privacy protocols, and we never share your clinic's data externally. Your practice's information stays yours.
No. Freed does not use Protected Health Information for AI training purposes. Our AI model is designed with HIPAA compliance at its core and is only trained on de-identified notes that have been stripped of all patient identifiers.
This means every conversation you have with patients is private. Our models are only trained on de-identified notes, and we don’t share your clinic’s data with external parties.
Freed is not FDA-approved, and it doesn't need to be. The FDA regulates software that functions as a medical device—tools that diagnose, treat, or directly affect patient health decisions.
Freed, on the other hand, is a clinical documentation platform that assists providers by transcribing and structuring notes from medical conversations. It doesn't make diagnostic suggestions, treatment recommendations, or clinical decisions. It falls outside the FDA's regulatory scope because it's a documentation tool, not a medical decision-making device.
Freed maintains HIPAA compliance through comprehensive security measures across multiple domains:
Internal personnel security:
Compliance framework:
Secure development:
Cloud infrastructure:
Network security:
Monitoring and response:
Freed's legal framework is designed to be fair and straightforward:
Mutual indemnification: You're covered if we cause legal issues (e.g., IP infringement); we're covered if Freed is misused or used without consent.
Standard liability cap: Set at 12 months of fees paid, with carveouts for gross negligence or breaches of confidentiality.
Termination and offboarding: We honor 30-day notice terms and support full data export or deletion upon request.
Business Associate Agreement: Our BAA is in use with hundreds of health systems and rarely requires edits. It covers your entire organization, ensuring HIPAA compliance for all users.
These terms protect both parties while ensuring you have the flexibility and control you need over your practice's data.
Yes. Freed provides robust access management capabilities:
For organizations, admins can centrally manage users, track adoption, and manage group settings such as SSO or MFA through built-in dashboards.
Yes, Freed provides detailed reporting for group admins to track usage, including visits, minutes, and provider activity. You can easily export this data for integration with your BI or analytics tools.
Reports can be downloaded in common formats like CSV, allowing you to combine Freed data with other business metrics for deeper insights into platform adoption, productivity, and documentation efficiency across your organization.
This transparency helps you measure ROI, track compliance, and identify opportunities for improving documentation workflows.
Freed offers admin reporting dashboards that make it easy to track adoption and usage across providers. You can monitor key metrics such as total visits, minutes recorded, and active users over time.
Data can be filtered by provider or department to identify engagement trends and partnership opportunities. For deeper analysis, reports can also be exported to CSV or integrated with your organization's BI tools to measure ongoing adoption and impact.
Each organization is also assigned a dedicated group account manager who partners with you to review adoption trends, share insights, and support rollout or engagement efforts.
Freed maintains strict vendor management protocols:
This ensures that even when working with third-party services, patient data remains protected to the same high standards throughout the entire technology stack.
Freed maintains comprehensive security monitoring and incident response capabilities:
24/7 monitoring:
Incident response:
Security audits:
Proactive security:
This multi-layered approach ensures that potential security issues are identified and addressed quickly, minimizing any risk to your practice.
Freed stands out in several ways:
Comprehensive certification: Freed is HIPAA-compliant, HITECH-aligned, and SOC 2 Type 2 certified, with cryptographic modules that follow FIPS PUB 140-2 standards.
No audio retention by default: Patient recordings are saved only until the note is completed and quality checks are done, then automatically deleted. There’s no long-term audio storage by default.
No training on PHI: Freed’s AI is only trained on de-identified notes. Protected health information is never used for AI training, helping protect patient privacy.
Storage in the U.S.: All data is processed and stored in U.S.-based Microsoft Azure data centers under a HIPAA-compliant BAA.
Transparent practices: Freed publishes clear documentation on security, data handling, and legal terms so IT and compliance teams can review details up front.
Proven track record: In use by hundreds of health systems and thousands of clinicians who have thoroughly vetted security practices.
Dedicated support: Each organization gets a dedicated account manager who understands your specific security requirements.
We're happy to connect your team with a Freed specialist—whether it's sales, legal, or technical. Security and compliance are too important to leave unanswered.
Contact us:
For organizations considering Freed, we can arrange calls with our security team, provide detailed documentation for your IT and compliance reviewers, and answer any technical questions your team has.
Your trust is our highest priority, and we're committed to providing complete transparency about how we protect patient data and maintain compliance.
You shouldn't have to choose between staying secure and staying above water. With Freed, you get both.
Join the thousands of clinicians who are simplifying charting with Freed.
Start a free trial to learn more about how Freed protects your practice.
Frequently asked questions from clinicians and medical practitioners.