PHI is processed as a HIPAA business associate under a signed BAA. The ambient scribe does not store patient audio.
This is a working draft prepared from the practices already described across this site. It has not been reviewed by counsel. Do not publish it as a binding policy until a qualified healthcare privacy attorney has reviewed it against your actual data flows, subprocessors and state-law obligations.
Codavia Health provides an electronic health record platform to healthcare organizations in the United States. This policy explains what we collect, how we use it, and the distinct roles we play with respect to two very different categories of information.
When a healthcare provider uses Codavia Health, that provider is the covered entity and Codavia Health acts as a business associate under HIPAA. We process PHI solely to provide the service, on the provider’s instructions, under a signed Business Associate Agreement (BAA). We do not own that PHI, we do not sell it, and we do not use it for advertising.
When you browse this website, request a demo, or administer an account, we act as the controller of that limited business-contact information. It is separate from PHI and is handled as described below.
The ambient scribe does not store patient audio. Audio is processed to produce a draft clinical note and is not retained as a recording. The resulting note becomes part of the patient record under the provider’s control, and the provider reviews and signs it.
We do not sell personal information or PHI. We do not use PHI to train general-purpose models outside the scope permitted by the applicable BAA.
We share information only with service providers who help us run the platform (for example hosting and infrastructure), each bound by written obligations at least as protective as those we accept, including BAAs where PHI is involved. Current subprocessors: [ list subprocessors ]
We may also disclose information where required by law, or to protect the rights, safety and security of patients, customers or the platform.
Security measures are described in detail on our security and compliance page and include encryption in transit and at rest, role-based access control, PHI audit logging, US-based hosting, and a completed SOC 2 audit. No system is perfectly secure, but PHI protection is designed in rather than added on.
PHI is retained according to the provider’s instructions and the terms of the BAA, and returned or destroyed on termination as that agreement requires. Business-contact and technical data is retained only as long as needed for the purposes above. Standard retention periods: [ specify retention periods ]
Patients: your rights of access, amendment and accounting of disclosures run through your healthcare provider, who controls your record. Please contact them directly — we will support them in responding.
Website visitors and account users: you may request access to, correction of, or deletion of the business-contact information we hold about you by emailing info@codavia.health. State-specific rights (including under applicable US state privacy laws): [ confirm applicable state laws ]
This site uses only what is necessary to serve and secure the pages. Cookie and analytics detail: [ confirm current cookie/analytics use ]
This website is not directed at children. PHI relating to pediatric patients is processed solely on the instruction of the treating provider under the BAA.
We will post any changes on this page and update the date above. Material changes affecting PHI handling will be communicated to affected customers directly.
Privacy questions, BAA requests and data enquiries: info@codavia.health. Privacy officer: [ name privacy officer ]
A 30-minute walkthrough on a live chart — ambient scribe, decision support, coding and the patient portal, end to end.
Book A Demo