Security & Compliance
Healthcare-grade protection for AI clinical documentation
Eva records a consult, drafts a clinically structured note, and hands it back to your clinician to review and finalize. Because Eva can process sensitive patient information, we treat security and data governance as part of the product, not a footnote.
This page describes what is true today. Where something is still being built, we mark it In progress, so this page also tracks what is left to finish.
Only a person puts a note in your record
This is the boundary that matters most: Eva produces a draft; a human decides.
- Eva captures and documents your clinical decisions. She does not make them.
- Eva never issues a diagnosis or a treatment decision as her own. Those come only from what your clinician says and decides.
- Nothing reaches the patient record unless someone on your team copies it there.
- Eva marks what still needs your confirmation, and records the sign-off when a clinician gives it. She does not force the step — you decide when a note is ready.
- Eva never writes notes into your practice-management system (PMS) on her own. The finalized note is copied in by your team.
- What Eva does read from your PMS, if you connect one: patient and provider details, on an import a member of your team triggers, never on a schedule of Eva's own. The only outbound write we plan is appointment booking, and it will never carry a note. A clinic set to standalone has no PMS connection at all.
Eva improves the completeness and consistency of your documentation. She does not replace clinical judgment, and she does not give legal or standard-of-care advice.
How Eva uses AI safely
Eva documents only what your consult evidenced.
Eva drafts every note from your captured consult (the transcript and your team's notes), never from another patient. She runs a set of specific checks over the draft and raises a flag when one trips: a tooth that was never mentioned, a pathology the consult does not support, a line that reads as sales talk. It is a set of checks rather than a guarantee that nothing slips past. Ambiguous findings stay general with a “please verify” marker. Where a routine check wasn't discussed, she can fill the template's expected normal and mark it “please verify” rather than inventing a finding, so an assumption is visible instead of silent. That coverage is partial today. Every note is a draft, and Eva cannot put it in your chart herself.
Your data does not train third-party AI models.
Patient data is never used to train our AI providers' models. We select providers that offer no-training / zero-retention terms.
Eva's own learning is opt-in and de-identified.
Eva improves herself from your data only if you opt in (this learning is off by default) and only from de-identified examples reviewed by our team. Never automatically, and never sent to a vendor for training.
What happens to your data
One consult, followed from the microphone to your chart. Eva never writes to your practice-management system; your team copies the note in, so you and your team decide what enters the record.
1 · Record the consult
You confirm recording consent, then record. Raw-audio retention is clinic-controlled; the options are under Your patients' data rights below.
2 · Clinical-tier transcript
Eva turns the audio into a transcript of what was actually said. The transcript is kept as part of your record even when the raw audio is later deleted.
3 · Source-grounded note
Eva drafts a note from that consult, then checks it back against what was said and raises a flag when one of its checks trips. Ambiguous findings stay general with a “please verify” marker rather than a guess.
4 · Chart-ready draft
Your team copies the finalized note into your PMS by clipboard. Eva never writes to your PMS on her own.
Security: how we protect your data
Each control below is in place today.
Per-clinic tenant isolation (at the database level)
Each clinic's data is isolated at the database level. One clinic cannot read, change, or even see another clinic's records. This is enforced in the database itself, not just in the application.
Encryption in transit
All connections use encrypted transport (TLS). Traffic to our database runs over a verified TLS channel, the application is HTTPS throughout, and outbound calls are refused over plaintext.
Encryption at rest (AES-256)
Stored data (including consult audio) is encrypted at rest with AES-256 by our cloud platform.
Approved-providers-only for patient data
Patient data is only ever sent to reviewed, approved providers. Anything not on the approved list is refused at the point of sending: it is blocked, not quietly used.
No patient data in system logs
Application logs carry structured identifiers and counts only — never patient content.
Error reports are structurally stripped
Before a crash report leaves Eva, identities, request bodies, query strings, the browser interaction trail's content and ad-hoc fields are removed. The error type, stack trace and system context are kept.
Tamper-evident audit trail
We keep an append-only record of key actions on your clinic's data: record changes, configuration changes, note copied to your practice system, and who opened which patient record or consult, per person, per day. Every entry can be added but never edited or deleted, so the record is tamper-evident. Clinic owners can view and export their access log in Eva; the detailed trail is available to you or your compliance reviewer on request.
Per-person sign-in & role-based access
Each team member signs in with their own personal code on the clinic account, and sign-ins, including failed attempts, are recorded. Roles set what each person can see: account and billing settings stay with the account holder, and clinical detail is limited to clinical roles, with per-person grants when an office runs differently.
Closing a case is signed for
A case closed later needs two signatures once your team has personal codes: a clinical sign-off and a team sign-off. Each shows who gave it, and reopening the case clears both. A clinic that has not issued codes yet signs off as the clinic account instead. A case finished during the visit itself is recorded as a same-visit completion, which is attested at the point it is created rather than collecting the two signatures afterwards.
Signed-in devices go stale on their own
A device left untouched for eight hours has to sign in again the next time someone uses it. The window is per device, not per person, because an operatory screen is shared. On clinics using team codes a shorter clock runs first: after three hours unused the device asks who is working, without signing anyone out.
Two-factor authentication (account login)
The practice owner can require an authenticator-app code to open the clinic account, so a stolen password alone won't get in; a remote sign-in without the owner's authenticator stops at the code screen. Opt-in per clinic, and already enforced on Eva's own account.
Your patients' data rights
Audio retention and deletion: you control it.
You choose what happens to raw consult recordings. Keep them indefinitely (the default), delete them once a note is signed off, or delete them after a set number of days. Only the raw audio is deleted this way; transcripts and clinical notes are kept as your record.
Recording consent and disclosure.
Eva's consult recorder confirms recording consent before a session begins. Eva also provides patient-facing disclosure wording for AI-assisted documentation and recorded consults. Consent law varies by jurisdiction, so the practice remains responsible for obtaining consent and meeting its local requirements. Eva enforces the recording-consent confirmation and supports the workflow.
Data export on request.
Clinics can delete patient records today. A portable patient-data export (a data subject access request, or DSAR) is being built — In progress.
Compliance by region
Eva is built as a global, multi-clinic product. What a clinic needs from us depends on where it operates and whose law governs its patients' data. We enable a region only when the controls that region requires are real for that clinic, and we render every requirement at its true status.
Guyana and the Caribbean (CARICOM): our first markets
In progressFor clinics operating under Guyana's Data Protection Act and comparable Caribbean data-protection law, Eva's posture is:
- Technical and organisational safeguards: the technical safeguards listed above, at the status each carries there. In place.
- A data-processing agreement (DPA) between Eva and your clinic, the correct instrument here (a US-style HIPAA BAA is not the instrument this region requires). Provided on request; put in place per clinic before real patient data.
- Patient consent and AI disclosure: explicit, specific, withdrawable consent for processing health data. Configured per clinic.
- A lawful cross-border-transfer basis: because our stack processes data outside Guyana, we agree the basis for that transfer with you in writing rather than leaving it unsaid. Agreed per clinic before go-live.
These are the instruments a clinic asks about most, not the whole regional checklist. We walk through the full list with you during onboarding, and confirm each one for your clinic before any real patient data.
United States: HIPAA (on the roadmap)
In progressEva is designed for HIPAA-aligned deployment. The technical safeguards a HIPAA deployment relies on are the ones listed above, at the status each carries there.
Before any US clinic processes real patient data (ePHI), signed Business Associate Agreements (BAAs) must be in place: between Eva and the clinic, and with the vendors that can touch that data. BAAs are available from our vendors; the signed BAAs are the remaining step. Eva's HIPAA status today: technical safeguards in place; the signed agreements and formal assessments behind a “HIPAA compliant” or “certified” label are in progress and tracked on this page. No Eva BAA is signed today, and Eva does not operate in US-HIPAA production-PHI mode; BAA status is confirmed per clinic before any real patient data. For clinics under Guyana's or other Caribbean data-protection law a BAA is not the instrument at all, and the DPA above is.
United Kingdom and EU: GDPR / UK GDPR (on the roadmap)
In progressFor UK and EU clinics, Eva is built toward GDPR / UK GDPR alignment with the clinic as controller and Eva as processor. Our data map and processing records exist today; a Data Processing Agreement (DPA), a data-protection impact assessment (DPIA), and a data export/erasure (DSAR) workflow are in progress.
Other regions
Clinics elsewhere are supported through a practice-specific review rather than a broad promise. Talk to us about your jurisdiction and we will tell you what is ready and what is not.
Vendors and subprocessors
Eva relies on a small set of vetted third parties for hosting, AI processing, and error monitoring, each under an appropriate agreement. AI healthcare buyers know third parties are involved; trust comes from being clear about who touches what and under what terms, and from refusing to send patient data to anything off the approved list.
Our specific architecture and vendor choices are proprietary. The full named subprocessor register (vendor names, the data each one touches, and the agreement covering it) is available to you and your compliance reviewer on request, under NDA. We do not publish the named vendor list on this page.
Our infrastructure providers hold independent security audits (SOC 2 Type 2) and an independent HIPAA attestation, which we have reviewed and keep on file; a general-use independent audit summary (SOC 3) can be shared with your compliance reviewer.
Documentation available on request
We prepare and provide the following to you or your compliance reviewer on request, under NDA. We show that we hold them; the contents stay request-only:
- Data Processing Agreement (DPA)
- Named subprocessor register
- Security overview
- Breach-response procedure
- Infrastructure-provider independent audit summary (SOC 3)
What's in place, and what we're still building
One live tracker.
In place today
- Per-clinic data isolation at the database level
- Encryption in transit (TLS) and at rest (AES-256)
- Approved-AI-providers-only for patient data
- Logs carry identifiers and counts, never patient content
- Tamper-evident, append-only audit trail
- Eva never writes into your practice-management system, never diagnoses, never decides treatment — only a person puts a note in your record
- Note sign-off recorded when a clinician gives it (Eva marks what needs confirming; she never forces the step)
- Clinic-controlled audio retention and deletion (audio only; transcripts and notes always kept)
- Two-factor authentication on the account login (authenticator app) — owner-managed, opt-in per clinic, enforced on Eva's operator account
- Eva's own learning is opt-in and de-identified
- Breach-response procedure (authored; regional notification timelines being counsel-confirmed per market)
In progress / on the roadmap
- Confirmed vendor no-training / zero-retention terms in signed agreements
- Portable patient-data export (DSAR)
- Signed Business Associate Agreements (BAAs) for US clinics
- Regional go-live instruments per clinic: DPA, consent, and cross-border-transfer basis (Guyana/Caribbean first)
No independent certification is held yet; the regional sections above track exactly where we are.
Talk to us
Bringing Eva to your clinic or reviewing her for a group? We are happy to walk your compliance reviewer through our posture and share the documentation above under NDA.
This page reflects Eva's controls as of 2026-08-30 and is maintained as they change. It describes platform controls; each practice remains responsible for consent, disclosure, and legal compliance in its own jurisdiction. This is not legal advice.