For clinicians
Privacy & security for clinicians
The short version — full policies live in Legal.
The short version
Fieldnote acts as your HIPAA Business Associate (US) or PIPEDA processor (Canada) — PHI is encrypted at rest and in transit, sign-in requires multi-factor authentication, and every access and write-back is captured in an audit trail. Our cloud provider is the only subprocessor with access to PHI, inside the same business associate agreement boundary as the rest of the pipeline.
This page is a clinician-facing summary. The complete, authoritative policies are on the Legal & compliance page — read those before relying on any statement here for a compliance decision.
Data residency
Your tenant is pinned to one data-center region at signup — US data centers for US practices, Canadian data centers for Canadian practices — and patient data never leaves that region. See Legal: Privacy Policy.
AI-assisted transcription and note drafting are gated off by default for Canadian tenants until an in-Canada AI processing path is available, unless your organization has separately and explicitly consented to a disclosed, audit-logged cross-border processing exception.
Recording consent
You are responsible for confirming patient consent before recording — see Recording a visit: patient consent for the exact script and statement, and Legal: recording consent for jurisdiction notes, including which US states require all-party consent.
Full policies
- Privacy Policy — what we collect, why, and your patients' rights.
- Terms of Service — your practice's agreement with Fieldnote.
- Business Associate Agreement — the HIPAA/PIPEDA data-handling contract.
- Security — encryption, access control, and incident response.